CVE-2012-4184
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not prevent access to properties of a prototype…
Does this matter?
Lower severity and a low EPSS score (1.80%). Track it; it rarely justifies an emergency change on its own.
Description
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not prevent access to properties of a prototype for a standard class, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.80% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- mozilla/firefox · mozilla/thunderbird esr · mozilla/thunderbird · mozilla/seamonkey · canonical/ubuntu linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation · suse/linux enterprise desktop · suse/linux enterprise sdk · suse/linux enterprise server
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.htmlMailing List, Third Party Advisory
- http://osvdb.org/86113Broken Link
- http://rhn.redhat.com/errata/RHSA-2012-1351.htmlThird Party Advisory
- http://secunia.com/advisories/50892Third Party Advisory
- http://secunia.com/advisories/50904Third Party Advisory
- http://secunia.com/advisories/50984Third Party Advisory
- http://secunia.com/advisories/55318Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:163Third Party Advisory
- http://www.mozilla.org/security/announce/2012/mfsa2012-83.htmlVendor Advisory
- http://www.securityfocus.com/bid/56120Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1611-1Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=780370Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79154Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16946Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.htmlMailing List, Third Party Advisory
- http://osvdb.org/86113Broken Link
- http://rhn.redhat.com/errata/RHSA-2012-1351.htmlThird Party Advisory
- http://secunia.com/advisories/50892Third Party Advisory
- http://secunia.com/advisories/50904Third Party Advisory
- http://secunia.com/advisories/50984Third Party Advisory
- http://secunia.com/advisories/55318Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:163Third Party Advisory
- http://www.mozilla.org/security/announce/2012/mfsa2012-83.htmlVendor Advisory
- http://www.securityfocus.com/bid/56120Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1611-1Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=780370Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79154Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16946Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.