SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-1944

The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not block inline event handlers, which…

MEDIUM 4.3EPSS 1.85%

Does this matter?

Lower severity and a low EPSS score (1.85%). Track it; it rarely justifies an emergency change on its own.

Description

The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not block inline event handlers, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
1.85% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird · mozilla/thunderbird esr
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.