SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-3991

Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which allows remote attackers to…

HIGH 9.3EPSS 3.08%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which allows remote attackers to bypass the Same Origin Policy and possibly have unspecified other impact via a crafted web site.

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
3.08% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
mozilla/firefox · mozilla/thunderbird esr · mozilla/thunderbird · mozilla/seamonkey · canonical/ubuntu linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation · suse/linux enterprise desktop · suse/linux enterprise sdk · suse/linux enterprise server
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.