CVE-2012-1944
The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not block inline event handlers, which…
Does this matter?
Lower severity and a low EPSS score (1.85%). Track it; it rarely justifies an emergency change on its own.
Description
The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not block inline event handlers, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.85% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird · mozilla/thunderbird esr
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00015.html
- http://rhn.redhat.com/errata/RHSA-2012-0710.html
- http://rhn.redhat.com/errata/RHSA-2012-0715.html
- http://secunia.com/advisories/49981Permissions Required
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:088
- http://www.mozilla.org/security/announce/2012/mfsa2012-36.htmlVendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=751422Issue Tracking
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17005
- http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00015.html
- http://rhn.redhat.com/errata/RHSA-2012-0710.html
- http://rhn.redhat.com/errata/RHSA-2012-0715.html
- http://secunia.com/advisories/49981Permissions Required
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:088
- http://www.mozilla.org/security/announce/2012/mfsa2012-36.htmlVendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=751422Issue Tracking
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17005
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.