SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-3978

The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 does not properly follow the security model of the location object,…

MEDIUM 6.8EPSS 2.30%

Does this matter?

Lower severity and a low EPSS score (2.30%). Track it; it rarely justifies an emergency change on its own.

Description

The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 does not properly follow the security model of the location object, which allows remote attackers to bypass intended content-loading restrictions or possibly have unspecified other impact via vectors involving chrome code.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
2.30% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
mozilla/firefox · mozilla/thunderbird esr · mozilla/thunderbird · mozilla/seamonkey
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.