CVE-2010-4209
Summary
| CVE | CVE-2010-4209 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-11-07 22:00:00 UTC |
| Updated | 2011-02-05 07:00:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.8.1, as used in Bugzilla 3.7.1 through 3.7.3 and 4.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to swfstore/swfstore.swf. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Bugzilla | 3.7.1 | All | All | All |
| Application | Mozilla | Bugzilla | 3.7.2 | All | All | All |
| Application | Mozilla | Bugzilla | 3.7.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1 | All | All | All |
| Application | Mozilla | Bugzilla | 3.7.1 | All | All | All |
| Application | Mozilla | Bugzilla | 3.7.2 | All | All | All |
| Application | Mozilla | Bugzilla | 3.7.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1 | All | All | All |
| Application | Yahoo | Yui | 2.8.0 | All | All | All |
| Application | Yahoo | Yui | 2.8.1 | All | All | All |
| Application | Yahoo | Yui | 2.8.0 | All | All | All |
| Application | Yahoo | Yui | 2.8.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:021 | SUSE | lists.opensuse.org | |
| SecurityTracker.com Archives - Bugzilla Permits Cross-Site Scripting and HTTP Response Splitting Attacks and Discloses Certain Information to Remote Users | SECTRACK | www.securitytracker.com | |
| YUI 2.8.2 Security Bulletin | CONFIRM | yuilibrary.com | Patch, Vendor Advisory |
| [SECURITY] Fedora 14 Update: bugzilla-3.6.3-1.fc14 | FEDORA | lists.fedoraproject.org | |
| oss-security - Re: CVE request: moodle 1.9.10 | MLIST | www.openwall.com | |
| [SECURITY] Fedora 12 Update: bugzilla-3.4.9-1.fc12 | FEDORA | lists.fedoraproject.org | |
| YUI Multiple Cross-Site Scripting Vulnerabilities - Advisories - Community | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| YUI Multiple Cross Site Scripting Vulnerabilities | BID | www.securityfocus.com | |
| Webmail | OVH- OVH | VUPEN | www.vupen.com | |
| Security Advisory SA42271 - Fedora update for bugzilla - Secunia | SECUNIA | secunia.com | |
| [SECURITY] Fedora 13 Update: bugzilla-3.4.9-1.fc13 | FEDORA | lists.fedoraproject.org | |
| 3.2.8, 3.4.8, 3.6.2, and 3.7.3 Security Advisory :: Bugzilla :: bugzilla.org | CONFIRM | www.bugzilla.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.