Summary
The host is installed with Mozilla Firefox and is prone to multiple vulnerabilities.
Impact
Successful exploitation will let attackers to bypass the Same Origin Policy and read the properties of a Location object via a crafted web site.
Impact Level: Application
Solution
Upgrade to Mozilla Firefox version 16.0.1 or later For updates refer to http://www.mozilla.com/en-US/firefox/all.html
Insight
Security wrappers are unwrapped without doing a security check in defaultValue(). This can allow for improper access to the Location object.
Affected
Mozilla Firefox versions before 16.0.1 on Mac OS X
References
Severity
Classification
-
CVE CVE-2012-4192, CVE-2012-4193 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe Flash Player Arbitrary Code Execution Vulnerability - 01 Feb14 (Windows)
- Adobe Acrobat Multiple Vulnerabilities - Windows
- Aastra IP Telephone Hardcoded Telnet Password Security Bypass Vulnerability
- Adobe Flash Player Code Execution and DoS Vulnerabilities (Linux)
- Adobe Acrobat Multiple Unspecified Vulnerabilities-01 Sep13 (Windows)