{"api_version":"1","generated_at":"2026-07-23T06:15:05+00:00","cve":"CVE-2011-2486","urls":{"html":"https://cve.report/CVE-2011-2486","api":"https://cve.report/api/cve/CVE-2011-2486.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-2486","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-2486"},"summary":{"title":"CVE-2011-2486","description":"nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.","state":"PUBLISHED","assigner":"redhat","published_at":"2012-11-19 12:10:48","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://rhn.redhat.com/errata/RHSA-2012-1459.html","name":"http://rhn.redhat.com/errata/RHSA-2012-1459.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://github.com/davidben/nspluginwrapper/commit/7e4ab8e1189846041f955e6c83f72bc1624e7a98","name":"https://github.com/davidben/nspluginwrapper/commit/7e4ab8e1189846041f955e6c83f72bc1624e7a98","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support all the new variables added · davidben/nspluginwrapper@7e4ab8e · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1027757","name":"http://www.securitytracker.com/id?1027757","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"nspluginwrapper NPNVprivateModeBool Variable Processing Flaw Lets Remote Users Deny Service - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.novell.com/show_bug.cgi?id=702034","name":"https://bugzilla.novell.com/show_bug.cgi?id=702034","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Access Denied","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lwn.net/Alerts/524725/","name":"http://lwn.net/Alerts/524725/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Scientific Linux alert SL-nspl-20121113 (nspluginwrapper) [LWN.net]","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=715384","name":"https://bugzilla.redhat.com/show_bug.cgi?id=715384","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug 715384 – CVE-2011-2486 nspluginwrapper does not forward NPNVprivateModeBool variable","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-2486","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-2486","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"2486","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nspluginwrapper","cpe5":"nspluginwrapper","cpe6":"1.4.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T23:00:34.025Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.novell.com/show_bug.cgi?id=702034"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/davidben/nspluginwrapper/commit/7e4ab8e1189846041f955e6c83f72bc1624e7a98"},{"name":"RHSA-2012:1459","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2012-1459.html"},{"name":"1027757","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1027757"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://lwn.net/Alerts/524725/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=715384"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2012-11-19T11:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.novell.com/show_bug.cgi?id=702034"},{"tags":["x_refsource_MISC"],"url":"https://github.com/davidben/nspluginwrapper/commit/7e4ab8e1189846041f955e6c83f72bc1624e7a98"},{"name":"RHSA-2012:1459","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2012-1459.html"},{"name":"1027757","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1027757"},{"tags":["x_refsource_MISC"],"url":"http://lwn.net/Alerts/524725/"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=715384"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2011-2486","datePublished":"2012-11-19T11:00:00.000Z","dateReserved":"2011-06-15T00:00:00.000Z","dateUpdated":"2024-08-06T23:00:34.025Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-11-19 12:10:48","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nspluginwrapper:nspluginwrapper:1.4.2:*:*:*:*:*:*:*","matchCriteriaId":"87E01B32-8F5C-4327-993B-7C43D1B45E7E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"2486","Ordinal":"1","Title":"CVE-2011-2486","CVE":"CVE-2011-2486","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"2486","Ordinal":"1","NoteData":"nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.","Type":"Description","Title":"CVE-2011-2486"},{"CveYear":"2011","CveId":"2486","Ordinal":"2","NoteData":"2012-11-19","Type":"Other","Title":"Published"}]}}}