CVE-2012-4192Mozilla Firefox vulnerability

CWE-2647 documents6 sources
Severity
4.3MEDIUMNVD
EPSS
0.9%
top 24.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 12
Latest updateMay 17

Description

Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same Origin Policy and read the properties of a Location object via a crafted web site, a related issue to CVE-2012-4193.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-632m-m565-j459: Mozilla Firefox 162022-05-17
CVEList
CVE-2012-4192: Mozilla Firefox 162012-10-12

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2012-10-12
Ubuntu
Firefox vulnerabilities2012-10-11
Red Hat
Mozilla: defaultValue security checks not applied (firefox-16) (MFSA 2012-89)2012-10-11

💬Community

1
Bugzilla
CVE-2012-4192 Mozilla: defaultValue security checks not applied (firefox-16) (MFSA 2012-89)2012-10-11
CVE-2012-4192 — Mozilla Firefox vulnerability | cvebase