SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-4205

Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XMLHttpRequest objects created in sandboxes, which allows remote attackers to conduct cross-site request…

MEDIUM 6.8EPSS 1.61%

Does this matter?

Lower severity and a low EPSS score (1.61%). Track it; it rarely justifies an emergency change on its own.

Description

Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XMLHttpRequest objects created in sandboxes, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks or obtain sensitive information by leveraging a sandboxed add-on.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
1.61% probability · 75th percentile
CISA KEV
Not listed
Weakness
CWE-352
Affected
mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird · canonical/ubuntu linux · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.