MEDIUM · 4.3

CVE-2012-5851

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remot...

Vulnerability Description

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
AppleWebkitAll versions
GoogleChrome<= 22.0.1229.96
AppleSafari5.1.7

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-5851?

CVE-2012-5851 is a vulnerability with a CVSS score of 4.3 (MEDIUM). html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remot...

How severe is CVE-2012-5851?

CVE-2012-5851 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-5851?

Check the references section above for vendor advisories and patch information. Affected products include: Apple Webkit, Google Chrome, Apple Safari.