CVE-2011-2486

Description

nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.235

Associated Vulnerability

VulnerabilityOS Platform
Nspluginwrapper update (CESA-2012:1459) nspluginwrapper-1.4.4-1.el6_3.i686.rpmLinux
Nspluginwrapper update (CESA-2012:1459) nspluginwrapper-1.4.4-1.el6_3.x86_64.rpmLinux
(RHSA-2012:1459) Low: nspluginwrapper security and bug fix update nspluginwrapper-1.4.4-1.el6_3.i686.rpmLinux
(RHSA-2012:1459) Low: nspluginwrapper security and bug fix update nspluginwrapper-1.4.4-1.el6_3.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234