CVE-2012-3985
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after…
Does this matter?
Lower severity and a low EPSS score (1.91%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.91% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird · canonical/ubuntu linux · suse/linux enterprise desktop · suse/linux enterprise server
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.htmlMailing List, Third Party Advisory
- http://osvdb.org/86106Broken Link
- http://secunia.com/advisories/50856Broken Link
- http://secunia.com/advisories/50892Broken Link
- http://secunia.com/advisories/50904Broken Link
- http://secunia.com/advisories/50935Broken Link
- http://secunia.com/advisories/50984Broken Link
- http://www.mozilla.org/security/announce/2012/mfsa2012-76.htmlVendor Advisory
- http://www.ubuntu.com/usn/USN-1611-1Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=655649Issue Tracking, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16108Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.htmlMailing List, Third Party Advisory
- http://osvdb.org/86106Broken Link
- http://secunia.com/advisories/50856Broken Link
- http://secunia.com/advisories/50892Broken Link
- http://secunia.com/advisories/50904Broken Link
- http://secunia.com/advisories/50935Broken Link
- http://secunia.com/advisories/50984Broken Link
- http://www.mozilla.org/security/announce/2012/mfsa2012-76.htmlVendor Advisory
- http://www.ubuntu.com/usn/USN-1611-1Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=655649Issue Tracking, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16108Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.