4

CVE-2013-1727

Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by using a symlink in conjunction with a file: URL for a local file.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MozillaFirefox Version <= 23.0.1
   GoogleAndroid
MozillaFirefox Version19.0
   GoogleAndroid
MozillaFirefox Version19.0.1
   GoogleAndroid
MozillaFirefox Version19.0.2
   GoogleAndroid
MozillaFirefox Version20.0
   GoogleAndroid
MozillaFirefox Version20.0.1
   GoogleAndroid
MozillaFirefox Version21.0
   GoogleAndroid
MozillaFirefox Version22.0
   GoogleAndroid
MozillaFirefox Version23.0
   GoogleAndroid
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.24% 0.839
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4 4.9 4.9
AV:N/AC:H/Au:N/C:P/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.