MEDIUM · 4.3

CVE-2012-0958

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain...

Vulnerability Description

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Ps Project Management TeamUnity-Firefox-Extension2.4.1

References

FAQ

What is CVE-2012-0958?

CVE-2012-0958 is a vulnerability with a CVSS score of 4.3 (MEDIUM). content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain...

How severe is CVE-2012-0958?

CVE-2012-0958 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-0958?

Check the references section above for vendor advisories and patch information. Affected products include: Ps Project Management Team Unity-Firefox-Extension.