CVE-2012-3965Mozilla Firefox vulnerability

CWE-2646 documents5 sources
Severity
9.3CRITICALNVD
EPSS
1.1%
top 21.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 29
Latest updateMay 17

Description

Mozilla Firefox before 15.0 does not properly restrict navigation to the about:newtab page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers creation of a new tab and then a new window.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDmozilla/firefox14.0+130

🔴Vulnerability Details

1
GHSA
GHSA-c6rc-75fx-qjhm: Mozilla Firefox before 152022-05-17

📋Vendor Advisories

3
Ubuntu
Firefox regression2012-09-11
Ubuntu
Firefox vulnerabilities2012-08-29
Red Hat
Mozilla: Escalation of privilege through about:newtab (MFSA 2012-60)2012-08-28

💬Community

1
Bugzilla
CVE-2012-3965 Mozilla: Escalation of privilege through about:newtab (MFSA 2012-60)2012-08-27