CVE-2012-3978 — Mozilla Firefox vulnerability
Severity
6.8MEDIUMNVD
EPSS
1.3%
top 20.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 29
Latest updateMay 17
Description
The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 does not properly follow the security model of the location object, which allows remote attackers to bypass intended content-loading restrictions or possibly have unspecified other impact via vectors involving chrome code.
CVSS vector
AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4
Affected Packages4 packages
🔴Vulnerability Details
2📋Vendor Advisories
3💬Community
1Bugzilla▶
CVE-2012-3978 Mozilla: Location object security checks bypassed by chrome code (MFSA 2012-70)↗2012-08-27