← Back

CVE-2012-5883

nvd nist
Published: Nov 16, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.9.0, as used in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web script or HTML via vectors related to swfstore.swf, a similar issue to CVE-2010-4209.

Affected (36)

Products: Mozilla: Bugzilla · Yahoo: Yui
1 product
Bugzilla
1 product
Yui
Configuration A
36 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 3.7.1
Version 3.7.2
Version 3.7.3
Version 3.7
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0.5
Version 4.0.6
Version 4.0.7
Version 4.0.8
Version 4.0
Version 4.0 rc1
Version 4.0 rc2
Version 4.1.1
Version 4.1.2
Version 4.1.3
Version 4.1
Version 4.2.1
Version 4.2.2
Version 4.2.3
Version 4.2
Version 4.2 rc1
Version 4.2 rc2
Version 4.3.1
Version 4.3.2
Version 4.3.3
Version 4.3
Yahoo
Version 2.8.0
Version 2.8.1
Version 2.8.1 pr1
Version 2.8.2
Version 2.9.0
Version 2.9.0 pr2
Version 2.9.0 pr4

References (16)

Timeline

No history available yet.