CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
Percentile
66.2%
content/unity-api.js in the unity-firefox-extension extension 2.4.1 for
Firefox exposes the toDataURL function in an API call, which allows remote
attackers to bypass the Same Origin Policy and obtain sensitive information
via a crafted webpage.
Author | Note |
---|---|
mdeslaur | security fix breaks ABI, and breaks some of the existing webapps. See bug for more information. |
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 12.10 | noarch | unity-firefox-extension | < 2.4.1-0ubuntu1.2 | UNKNOWN |