VDB
CVE-2010-2809
CVE-2010-2809
PUBLISHED
CVSS 6.800000190734863 MEDIUM
The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assisted remote attackers to execute arbitrary commands via a crafted HREF attribute of an A element in an HTML document.
EPSS 5.77% · 90.6th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
5.77%
90.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| uzbl | uzbl | 2010.01.04, 2009.12.22, 0 |
| n/a | n/a | n/a |
Timeline
- Aug 19, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- http://github.com/Dieterbe/uzbl/commit/9cc39cb5c9396be013b5dc2ba7e4b3eaa647e975 url
- http://github.com/pawelz/uzbl/commit/342f292c27973c9df5f631a38bd12f14a9c5cdc2 url
- https://bugzilla.redhat.com/show_bug.cgi?id=621964 url
- [oss-security] 20100806 CVE request: uzbl before 2010.08.05: User-assisted execution of arbitrary commands caused by faulty default config mailing-list
- [oss-security] 20100806 Re: CVE request: uzbl before 2010.08.05: User-assisted execution of arbitrary commands caused by faulty default config mailing-list
- http://www.uzbl.org/news.php?id=29 url
- 42297 vdb
- http://www.uzbl.org/bugs/index.php?do=details&task_id=240 url
- https://bugzilla.redhat.com/show_bug.cgi?id=621965 url
- uzbl-atselecteduri-command-execution(61011) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2010-2809 advisory