CVE-2012-4193
Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers,…
Does this matter?
Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-346
- Affected
- mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird · mozilla/thunderbird esr · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · canonical/ubuntu linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1361.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1362.htmlThird Party Advisory
- http://secunia.com/advisories/50904Third Party Advisory
- http://secunia.com/advisories/50906Third Party Advisory
- http://secunia.com/advisories/50907Third Party Advisory
- http://secunia.com/advisories/50964Third Party Advisory
- http://secunia.com/advisories/50984Third Party Advisory
- http://secunia.com/advisories/55318Third Party Advisory
- http://www.mozilla.org/security/announce/2012/mfsa2012-89.htmlVendor Advisory
- http://www.ubuntu.com/usn/USN-1611-1Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=720619Exploit, Issue Tracking, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79211Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16786Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1361.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1362.htmlThird Party Advisory
- http://secunia.com/advisories/50904Third Party Advisory
- http://secunia.com/advisories/50906Third Party Advisory
- http://secunia.com/advisories/50907Third Party Advisory
- http://secunia.com/advisories/50964Third Party Advisory
- http://secunia.com/advisories/50984Third Party Advisory
- http://secunia.com/advisories/55318Third Party Advisory
- http://www.mozilla.org/security/announce/2012/mfsa2012-89.htmlVendor Advisory
- http://www.ubuntu.com/usn/USN-1611-1Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=720619Exploit, Issue Tracking, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79211Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16786Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.