CVE-2012-2889

Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to inject arbitrary web script or HTML via vectors involving frames, aka "Universal XSS (UXSS)."
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.0:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.1:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.2:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.3:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.4:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.6:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.7:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.8:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.9:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.10:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.11:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.12:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.14:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.16:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.17:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.18:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.20:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.21:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.22:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.23:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.24:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.25:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.26:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.27:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.28:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.29:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.31:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.32:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.33:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.35:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.36:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.37:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.39:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.48:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.49:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.50:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.51:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.52:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.53:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.54:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.55:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.56:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.57:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.58:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.59:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.60:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.62:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.63:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.64:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.65:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.67:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:22.0.1229.76:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:6.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:6.0.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:39

Type Values Removed Values Added
References () http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html - () http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html -
References () http://lists.apple.com/archives/security-announce/2013/Jan/msg00000.html - () http://lists.apple.com/archives/security-announce/2013/Jan/msg00000.html -
References () http://lists.apple.com/archives/security-announce/2013/Mar/msg00003.html - () http://lists.apple.com/archives/security-announce/2013/Mar/msg00003.html -
References () http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00012.html - () http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00012.html -
References () http://support.apple.com/kb/HT5642 - () http://support.apple.com/kb/HT5642 -
References () https://code.google.com/p/chromium/issues/detail?id=143439 - () https://code.google.com/p/chromium/issues/detail?id=143439 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/78823 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/78823 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15829 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15829 -

07 Nov 2023, 02:11

Type Values Removed Values Added
References (CONFIRM) https://code.google.com/p/chromium/issues/detail?id=143439 - () https://code.google.com/p/chromium/issues/detail?id=143439 -
References (CONFIRM) http://support.apple.com/kb/HT5642 - () http://support.apple.com/kb/HT5642 -
References (CONFIRM) http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html - Vendor Advisory () http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html -
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00012.html - () http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00012.html -
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/78823 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/78823 -
References (APPLE) http://lists.apple.com/archives/security-announce/2013/Jan/msg00000.html - () http://lists.apple.com/archives/security-announce/2013/Jan/msg00000.html -
References (APPLE) http://lists.apple.com/archives/security-announce/2013/Mar/msg00003.html - () http://lists.apple.com/archives/security-announce/2013/Mar/msg00003.html -

Information

Published : 2012-09-26 10:56

Updated : 2024-11-21 01:39


NVD link : CVE-2012-2889

Mitre link : CVE-2012-2889

CVE.ORG link : CVE-2012-2889


JSON object : View

Products Affected

apple

  • iphone_os

google

  • chrome
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')