MidnightBSD

Advisories for yoono

CVE-2009-4100 HIGH

Yoono extension before 6.1.1 for Firefox performs certain operations with chrome privileges, which allows user-assisted remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via DOM event handlers such as onload.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
yoono yoono *
yoono yoono 5.1.0
yoono yoono 3.1.1.2999
yoono yoono 2.0.2.474
yoono yoono 3.1.0.2898
yoono yoono 6.0.1
yoono yoono 5.0.7.2
yoono yoono 2.0.3.564
yoono yoono 3.0.1.1388
yoono yoono 2.0.4.641
yoono yoono 5.0.5
yoono yoono 3.0.6.2723
yoono yoono 2.1.0.743
yoono yoono 5.0.7
yoono yoono 4.0.2.5149
yoono yoono 2.2.1.1038
yoono yoono 5.0.1.11511_11520
yoono yoono 4.0.3.5488
yoono yoono 3.0.0.1268
yoono yoono 3.0.5.2626
yoono yoono 4.0.0.4529
yoono yoono 5.0.3
yoono yoono 4.0.1.4774
yoono yoono 3.0.4.2469
yoono yoono 5.0.6
yoono yoono 5.0.4
yoono yoono 6.0.0
yoono yoono 3.0.2.1976
yoono yoono 3.0.3.2369
yoono yoono 5.3.0
yoono yoono 5.2.0
yoono yoono 5.4.0
yoono yoono 3.0.0.1270
CVE-2012-1214 MEDIUM

Cross-site scripting (XSS) vulnerability in the Add friends module in Yoono Desktop Application before 1.8.21 allows remote attackers to inject arbitrary web script or HTML via the create field in a "Create a group" action.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
yoono yoono_desktop *
CVE-2012-1215 MEDIUM

Cross-site scripting (XSS) vulnerability in the Add friends module in the Yoono extension before 7.7.8 for Firefox allows remote attackers to inject arbitrary web script or HTML via the create field in a "Create a group" action.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
yoono yoono_for_firefox *