CVE-2012-5851
Summary
| CVE | CVE-2012-5851 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-11-15 11:58:40 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apple | Safari | 5.1.7 | All | All | All |
| Application | Apple | Webkit | All | All | All | All |
| Application | Chrome | 22.0.1229.0 | All | All | All | |
| Application | Chrome | 22.0.1229.1 | All | All | All | |
| Application | Chrome | 22.0.1229.10 | All | All | All | |
| Application | Chrome | 22.0.1229.11 | All | All | All | |
| Application | Chrome | 22.0.1229.12 | All | All | All | |
| Application | Chrome | 22.0.1229.14 | All | All | All | |
| Application | Chrome | 22.0.1229.16 | All | All | All | |
| Application | Chrome | 22.0.1229.17 | All | All | All | |
| Application | Chrome | 22.0.1229.18 | All | All | All | |
| Application | Chrome | 22.0.1229.2 | All | All | All | |
| Application | Chrome | 22.0.1229.20 | All | All | All | |
| Application | Chrome | 22.0.1229.21 | All | All | All | |
| Application | Chrome | 22.0.1229.22 | All | All | All | |
| Application | Chrome | 22.0.1229.23 | All | All | All | |
| Application | Chrome | 22.0.1229.24 | All | All | All | |
| Application | Chrome | 22.0.1229.25 | All | All | All | |
| Application | Chrome | 22.0.1229.26 | All | All | All | |
| Application | Chrome | 22.0.1229.27 | All | All | All | |
| Application | Chrome | 22.0.1229.28 | All | All | All | |
| Application | Chrome | 22.0.1229.29 | All | All | All | |
| Application | Chrome | 22.0.1229.3 | All | All | All | |
| Application | Chrome | 22.0.1229.31 | All | All | All | |
| Application | Chrome | 22.0.1229.32 | All | All | All | |
| Application | Chrome | 22.0.1229.33 | All | All | All | |
| Application | Chrome | 22.0.1229.35 | All | All | All | |
| Application | Chrome | 22.0.1229.36 | All | All | All | |
| Application | Chrome | 22.0.1229.37 | All | All | All | |
| Application | Chrome | 22.0.1229.39 | All | All | All | |
| Application | Chrome | 22.0.1229.4 | All | All | All | |
| Application | Chrome | 22.0.1229.48 | All | All | All | |
| Application | Chrome | 22.0.1229.49 | All | All | All | |
| Application | Chrome | 22.0.1229.50 | All | All | All | |
| Application | Chrome | 22.0.1229.51 | All | All | All | |
| Application | Chrome | 22.0.1229.52 | All | All | All | |
| Application | Chrome | 22.0.1229.53 | All | All | All | |
| Application | Chrome | 22.0.1229.54 | All | All | All | |
| Application | Chrome | 22.0.1229.55 | All | All | All | |
| Application | Chrome | 22.0.1229.56 | All | All | All | |
| Application | Chrome | 22.0.1229.57 | All | All | All | |
| Application | Chrome | 22.0.1229.58 | All | All | All | |
| Application | Chrome | 22.0.1229.59 | All | All | All | |
| Application | Chrome | 22.0.1229.6 | All | All | All | |
| Application | Chrome | 22.0.1229.60 | All | All | All | |
| Application | Chrome | 22.0.1229.62 | All | All | All | |
| Application | Chrome | 22.0.1229.63 | All | All | All | |
| Application | Chrome | 22.0.1229.64 | All | All | All | |
| Application | Chrome | 22.0.1229.65 | All | All | All | |
| Application | Chrome | 22.0.1229.67 | All | All | All | |
| Application | Chrome | 22.0.1229.7 | All | All | All | |
| Application | Chrome | 22.0.1229.76 | All | All | All | |
| Application | Chrome | 22.0.1229.78 | All | All | All | |
| Application | Chrome | 22.0.1229.79 | All | All | All | |
| Application | Chrome | 22.0.1229.8 | All | All | All | |
| Application | Chrome | 22.0.1229.89 | All | All | All | |
| Application | Chrome | 22.0.1229.9 | All | All | All | |
| Application | Chrome | 22.0.1229.91 | All | All | All | |
| Application | Chrome | 22.0.1229.92 | All | All | All | |
| Application | Chrome | 22.0.1229.94 | All | All | All | |
| Application | Chrome | 22.0.1229.95 | All | All | All | |
| Application | Chrome | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Bug 92692 – WebKit XSS Auditor bypass | af854a3a-2127-422b-91ae-364da2661108 | bugs.webkit.org | Exploit |
| Open Security Research: Simple Cross Site Scripting Vector That Webkit XSS Auditor Ignores | af854a3a-2127-422b-91ae-364da2661108 | blog.opensecurityresearch.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.