VDB
CVE-2011-3635
CVE-2011-3635
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted alias (aka nickname).
EPSS 1.96% · 79.7th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
1.96%
79.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| gnome | empathy | 0.1, 0.2, 0.3 |
Timeline
- Oct 23, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 12, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- May 29, 2023 EPSS Score
- Jul 21, 2023 EPSS Score
References
- https://bugzilla.redhat.com/show_bug.cgi?id=747599 url
- http://git.gnome.org/browse/empathy/commit/?id=739aca418457de752be13721218aaebc74bd9d36 url
- 50323 vdb
- http://osvdb.org/76485 technical
- http://secunia.com/advisories/46510 advisory
- http://secunia.com/advisories/46939 technical
- https://nvd.nist.gov/vuln/detail/CVE-2011-3635 advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=662035 url