VulnerabilityModified
CVE-2012-4192
Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same Origin Policy and read the properties of a Location object via a crafted web site, a related issue to CVE-2012-4193.
MEDIUM 4.3EPSS 1.41%
Does this matter?
Lower severity and a low EPSS score (1.41%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same Origin Policy and read the properties of a Location object via a crafted web site, a related issue to CVE-2012-4193.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.41% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.html
- http://secunia.com/advisories/50904
- http://secunia.com/advisories/50929
- http://secunia.com/advisories/50984
- http://secunia.com/advisories/55318
- http://www.mozilla.org/security/announce/2012/mfsa2012-89.htmlVendor Advisory
- http://www.thespanner.co.uk/2012/10/10/firefox-knows-what-your-friends-did-last-summer/Exploit
- http://www.ubuntu.com/usn/USN-1608-1
- http://www.ubuntu.com/usn/USN-1611-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=799952
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79210
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17095
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.html
- http://secunia.com/advisories/50904
- http://secunia.com/advisories/50929
- http://secunia.com/advisories/50984
- http://secunia.com/advisories/55318
- http://www.mozilla.org/security/announce/2012/mfsa2012-89.htmlVendor Advisory
- http://www.thespanner.co.uk/2012/10/10/firefox-knows-what-your-friends-did-last-summer/Exploit
- http://www.ubuntu.com/usn/USN-1608-1
- http://www.ubuntu.com/usn/USN-1611-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=799952
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79210
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17095
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.