VYPR

unity-firefox-extension

by Canonical

CVEs (3)

  • CVE-2013-1055MedApr 7, 2021
    risk 0.28cvss 4.3epss 0.01

    The unity-firefox-extension package could be tricked into dropping a C callback which was still in use, which Firefox would then free, causing Firefox to crash. This could be achieved by adding an action to the launcher and updating it with new callbacks until the…

  • CVE-2013-1054MedApr 7, 2021
    risk 0.28cvss 4.3epss 0.01

    The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an…

  • CVE-2012-0960Nov 24, 2012
    risk 0.00cvss epss 0.03

    Unity integration extension (unity-firefox-extension) before 2.4.1 for Firefox does not properly handle callbacks, which allows remote attackers to cause a denial of service (Firefox crash) and possibly execute arbitrary code via a crafted request.