CVE-2012-1945Sensitive Information Exposure in Mozilla Seamonkey

Severity
2.9LOWNVD
EPSS
0.2%
top 58.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 5
Latest updateMay 14

Description

Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow local users to obtain sensitive information via an HTML document that loads a shortcut (aka .lnk) file for display within an IFRAME element, as demonstrated by a network share implemented by (1) Microsoft Windows or (2) Samba.

CVSS vector

AV:A/AC:M/C:P/I:N/A:NExploitability: 5.5 | Impact: 2.9

Affected Packages4 packages

NVDmozilla/firefox20 versions+19
NVDmozilla/thunderbird16 versions+15
NVDmozilla/thunderbird_esr5 versions+4
NVDmozilla/seamonkey2.9+64

🔴Vulnerability Details

2
GHSA
GHSA-xqrh-6pmp-4rgf: Mozilla Firefox 42022-05-14
CVEList
CVE-2012-1945: Mozilla Firefox 42012-06-05

📋Vendor Advisories

4
Ubuntu
Thunderbird vulnerabilities2012-06-27
Ubuntu
Firefox regressions2012-06-20
Ubuntu
Firefox vulnerabilities2012-06-06
Red Hat
Mozilla: Information disclosure though Windows file shares and shortcut files (MFSA 2012-37)2012-06-05

💬Community

1
Bugzilla
CVE-2012-1945 Mozilla: Information disclosure though Windows file shares and shortcut files (MFSA 2012-37)2012-06-03
CVE-2012-1945 — Sensitive Information Exposure | cvebase