Cross Site Scripting (XSS) vulnerability in uBlock Origin extension before 1.41.1 allows remote attackers to run arbitrary code via a spoofed 'MessageSender.url' to the browser renderer process.
{ "binaries": [ { "binary_version": "1.6.6+dfsg-1", "binary_name": "xul-ext-ublock-origin" } ] }
{ "binaries": [ { "binary_version": "1.13.8+dfsg-1", "binary_name": "chromium-ublock-origin" }, { "binary_version": "1.13.8+dfsg-1", "binary_name": "xul-ext-ublock-origin" } ] }
{ "binaries": [ { "binary_version": "1.22.2+dfsg-1", "binary_name": "chromium-ublock-origin" }, { "binary_version": "1.22.2+dfsg-1", "binary_name": "webext-ublock-origin" }, { "binary_version": "1.22.2+dfsg-1", "binary_name": "xul-ext-ublock-origin" } ] }
{ "binaries": [ { "binary_version": "1.40.2+dfsg-1", "binary_name": "webext-ublock-origin" }, { "binary_version": "1.40.2+dfsg-1", "binary_name": "webext-ublock-origin-chromium" }, { "binary_version": "1.40.2+dfsg-1", "binary_name": "webext-ublock-origin-firefox" } ] }