CVE-2012-3975Sensitive Information Exposure in Mozilla Firefox

Severity
4.3MEDIUMNVD
EPSS
0.9%
top 23.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 29
Latest updateMay 17

Description

The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 loads subresources during parsing of text/html data within an extension, which allows remote attackers to obtain sensitive information by providing crafted data to privileged extension code.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/firefox14.0+130
NVDmozilla/seamonkey2.11+32
NVDmozilla/thunderbird14.0+99

🔴Vulnerability Details

2
GHSA
GHSA-h9mf-392q-233m: The DOMParser component in Mozilla Firefox before 152022-05-17
CVEList
CVE-2012-3975: The DOMParser component in Mozilla Firefox before 152012-08-29

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2012-08-30
Ubuntu
Firefox vulnerabilities2012-08-29
Red Hat
Mozilla: DOMParser loads linked resources in extensions when parsing text/html (MFSA 2012-68)2012-08-28

💬Community

1
Bugzilla
CVE-2012-3975 Mozilla: DOMParser loads linked resources in extensions when parsing text/html (MFSA 2012-68)2012-08-27
CVE-2012-3975 — Sensitive Information Exposure | cvebase