[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-3973Date: (C)2012-08-29   (M)2024-03-27


The debugger in the developer-tools subsystem in Mozilla Firefox before 15.0, when remote debugging is disabled, does not properly restrict access to the remote-debugging service, which allows remote attackers to execute arbitrary code by leveraging the presence of the HTTPMonitor extension and connecting to that service through the HTTPMonitor port.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.6
Exploit Score: 4.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
BID-55308
OSVDB-85005
SUSE-SU-2012:1157
SUSE-SU-2012:1167
USN-1548-1
USN-1548-2
http://www.mozilla.org/security/announce/2012/mfsa2012-66.html
https://bugzilla.mozilla.org/show_bug.cgi?id=757128
openSUSE-SU-2012:1065
oval:org.mitre.oval:def:17039

CPE    147
cpe:/a:mozilla:firefox:14.0
cpe:/a:mozilla:firefox:10.0
cpe:/a:mozilla:firefox:3.5.7
cpe:/a:mozilla:firefox:3.5.8
...
CWE    1
CWE-264
OVAL    8
oval:org.secpod.oval:def:400428
oval:org.secpod.oval:def:400421
oval:org.secpod.oval:def:700982
oval:org.secpod.oval:def:302958
...

© SecPod Technologies