nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade nspluginwrapper | Dec 1, 2016 | Nov 19, 2012 |
| Oracle_linux | — | Upgrade nspluginwrapper | Oct 16, 2024 | Nov 19, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 25, 2011 |
| Suse | — | Upgrade nspluginwrapper | Dec 12, 2013 | Nov 19, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub