CVE Vulnerabilities

CVE-2010-0011

Published: Feb 25, 2010 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The eval_js function in uzbl-core.c in Uzbl before 2010.01.05 exposes the run method of the Uzbl object, which allows remote attackers to execute arbitrary commands via JavaScript code.

Affected Software

Name Vendor Start Version End Version
Uzbl Uzbl * 2009.12.22 (including)
Uzbl Ubuntu maverick *
Uzbl Ubuntu natty *
Uzbl Ubuntu oneiric *
Uzbl Ubuntu quantal *
Uzbl Ubuntu raring *
Uzbl Ubuntu saucy *

References