CVE-2012-3994
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to conduct cross-site scripting (XSS) attacks via a binary plugin that uses…
Does this matter?
Lower severity and a low EPSS score (2.39%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to conduct cross-site scripting (XSS) attacks via a binary plugin that uses Object.defineProperty to shadow the top object, and leverages the relationship between top.location and the location property.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.39% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- mozilla/firefox · mozilla/thunderbird esr · mozilla/thunderbird · mozilla/seamonkey · suse/linux enterprise desktop · suse/linux enterprise sdk · suse/linux enterprise server · canonical/ubuntu linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.htmlThird Party Advisory
- http://osvdb.org/86110Broken Link
- http://rhn.redhat.com/errata/RHSA-2012-1351.htmlThird Party Advisory
- http://secunia.com/advisories/50856Third Party Advisory
- http://secunia.com/advisories/50892Third Party Advisory
- http://secunia.com/advisories/50904Third Party Advisory
- http://secunia.com/advisories/50935Third Party Advisory
- http://secunia.com/advisories/50936Third Party Advisory
- http://secunia.com/advisories/50984Third Party Advisory
- http://secunia.com/advisories/55318Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:163Third Party Advisory
- http://www.mozilla.org/security/announce/2012/mfsa2012-82.htmlVendor Advisory
- http://www.securityfocus.com/bid/56118Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1611-1Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=765527Issue Tracking, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16798Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.htmlThird Party Advisory
- http://osvdb.org/86110Broken Link
- http://rhn.redhat.com/errata/RHSA-2012-1351.htmlThird Party Advisory
- http://secunia.com/advisories/50856Third Party Advisory
- http://secunia.com/advisories/50892Third Party Advisory
- http://secunia.com/advisories/50904Third Party Advisory
- http://secunia.com/advisories/50935Third Party Advisory
- http://secunia.com/advisories/50936Third Party Advisory
- http://secunia.com/advisories/50984Third Party Advisory
- http://secunia.com/advisories/55318Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:163Third Party Advisory
- http://www.mozilla.org/security/announce/2012/mfsa2012-82.htmlVendor Advisory
- http://www.securityfocus.com/bid/56118Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1611-1Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.