4

CVE-2013-1727

Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by using a symlink in conjunction with a file: URL for a local file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version <= 23.0.1
   Google ≫ Android
Mozilla ≫ Firefox Version 19.0
   Google ≫ Android
Mozilla ≫ Firefox Version 19.0.1
   Google ≫ Android
Mozilla ≫ Firefox Version 19.0.2
   Google ≫ Android
Mozilla ≫ Firefox Version 20.0
   Google ≫ Android
Mozilla ≫ Firefox Version 20.0.1
   Google ≫ Android
Mozilla ≫ Firefox Version 21.0
   Google ≫ Android
Mozilla ≫ Firefox Version 22.0
   Google ≫ Android
Mozilla ≫ Firefox Version 23.0
   Google ≫ Android
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.19% 0.914
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 4.9 4.9
AV:N/AC:H/Au:N/C:P/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115907.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116610.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-September/117526.html
http://www.mozilla.org/security/announce/2013/mfsa2013-84.html
Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=782581