CVE-2012-0958
Ubuntu Security Notice USN-1665-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.
content/unity-api.js en la extensión unity-firefox-extensión para Firefox v2.4.1 expone la función toDataURL en una llamada a la API, lo que permite a atacantes remotos evitar la política del mismo origen y obtener información sensible a través de una página web modificada para tal fin.
It was discovered that unity-firefox-extension bypassed the same origin policy checks in certain circumstances. If a user were tricked into opening a malicious page, an attacker could exploit this to steal confidential data or perform other security-sensitive operations.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-02-01 CVE Reserved
- 2012-12-14 CVE Published
- 2024-09-16 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://bazaar.launchpad.net/~webapps/unity-firefox-extension/trunk/revision/331 | X_refsource_confirm | |
http://osvdb.org/88438 | Vdb Entry | |
http://www.securityfocus.com/bid/56930 | Vdb Entry | |
https://bugs.launchpad.net/ubuntu/%2Bsource/unity-firefox-extension/%2Bbug/1069817 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.ubuntu.com/usn/USN-1665-1 | 2013-01-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ps Project Management Team Search vendor "Ps Project Management Team" | Unity-firefox-extension Search vendor "Ps Project Management Team" for product "Unity-firefox-extension" | 2.4.1 Search vendor "Ps Project Management Team" for product "Unity-firefox-extension" and version "2.4.1" | firefox |
Affected
|