CVE-2012-4208
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass intended chrome-only restrictions on…
Does this matter?
Lower severity and a low EPSS score (2.11%). Track it; it rarely justifies an emergency change on its own.
Description
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass intended chrome-only restrictions on reading DOM object properties via a crafted web site.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 2.11% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00021.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00022.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-11/msg00090.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-11/msg00092.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-11/msg00093.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/51369Third Party Advisory
- http://secunia.com/advisories/51370Third Party Advisory
- http://secunia.com/advisories/51381Third Party Advisory
- http://secunia.com/advisories/51434Third Party Advisory
- http://secunia.com/advisories/51439Third Party Advisory
- http://secunia.com/advisories/51440Third Party Advisory
- http://www.mozilla.org/security/announce/2012/mfsa2012-99.htmlVendor Advisory
- http://www.securityfocus.com/bid/56627Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1636-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-1638-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-1638-2Third Party Advisory
- http://www.ubuntu.com/usn/USN-1638-3Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=798264Issue Tracking, Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16695Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00021.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00022.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-11/msg00090.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-11/msg00092.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-11/msg00093.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/51369Third Party Advisory
- http://secunia.com/advisories/51370Third Party Advisory
- http://secunia.com/advisories/51381Third Party Advisory
- http://secunia.com/advisories/51434Third Party Advisory
- http://secunia.com/advisories/51439Third Party Advisory
- http://secunia.com/advisories/51440Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.