← Back

CVE-2012-5851

nvd nist
Published: Nov 15, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.

Affected (62)

Products: Google: Chrome · Apple: Safari, Webkit
1 product
Chrome
2 products
Safari
Webkit
Configuration A
60 vulnerable
Vulnerable SoftwareAffected Versions
Google
Up to 22.0.1229.96
Version 22.0.1229.0
Version 22.0.1229.10
Version 22.0.1229.11
Version 22.0.1229.12
Version 22.0.1229.14
Version 22.0.1229.16
Version 22.0.1229.17
Version 22.0.1229.18
Version 22.0.1229.1
Version 22.0.1229.20
Version 22.0.1229.21
Version 22.0.1229.22
Version 22.0.1229.23
Version 22.0.1229.24
Version 22.0.1229.25
Version 22.0.1229.26
Version 22.0.1229.27
Version 22.0.1229.28
Version 22.0.1229.29
Version 22.0.1229.2
Version 22.0.1229.31
Version 22.0.1229.32
Version 22.0.1229.33
Version 22.0.1229.35
Version 22.0.1229.36
Version 22.0.1229.37
Version 22.0.1229.39
Version 22.0.1229.3
Version 22.0.1229.48
Version 22.0.1229.49
Version 22.0.1229.4
Version 22.0.1229.50
Version 22.0.1229.51
Version 22.0.1229.52
Version 22.0.1229.53
Version 22.0.1229.54
Version 22.0.1229.55
Version 22.0.1229.56
Version 22.0.1229.57
Version 22.0.1229.58
Version 22.0.1229.59
Version 22.0.1229.60
Version 22.0.1229.62
Version 22.0.1229.63
Version 22.0.1229.64
Version 22.0.1229.65
Version 22.0.1229.67
Version 22.0.1229.6
Version 22.0.1229.76
Version 22.0.1229.78
Version 22.0.1229.79
Version 22.0.1229.7
Version 22.0.1229.89
Version 22.0.1229.8
Version 22.0.1229.91
Version 22.0.1229.92
Version 22.0.1229.94
Version 22.0.1229.95
Version 22.0.1229.9
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.1.7
All versions

Timeline

No history available yet.