CVE-2012-0455Cross-site Scripting in Mozilla Firefox

CWE-79Cross-site Scripting13 documents6 sources
Severity
4.3MEDIUMNVD
EPSS
1.1%
top 21.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 14
Latest updateMay 4

Description

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web page, related to a "DragAndDropJacking" issue.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages5 packages

NVDmozilla/firefox3.6.27+14
NVDmozilla/thunderbird3.1.19+7
NVDmozilla/firefox_esr10.1, 10.2+1
NVDmozilla/thunderbird_esr10.0, 10.0.1, 10.0.2+2

🔴Vulnerability Details

2
GHSA
GHSA-v6mh-5q54-hvfp: Mozilla Firefox before 32022-05-04
CVEList
CVE-2012-0455: Mozilla Firefox before 32012-03-14

📋Vendor Advisories

8
Ubuntu
GSettings desktop schemas regression2012-04-20
Ubuntu
Thunderbird regressions2012-04-03
Ubuntu
Thunderbird vulnerabilities2012-03-23
Ubuntu
Thunderbird vulnerabilities2012-03-21
Ubuntu
Xulrunner vulnerabilities2012-03-19

💬Community

1
Bugzilla
CVE-2012-0455 Mozilla: XSS with Drag and Drop and Javascript: URL (MFSA 2012-13)2012-03-14
CVE-2012-0455 — Cross-site Scripting in Mozilla Firefox | cvebase