CVE-2012-4195
published 2012-10-29CVE-2012-4195: The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.90%
77.4th percentile
The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 does not properly determine the calling document and principal in its return value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site, and makes it easier for remote attackers to execute arbitrary JavaScript code by leveraging certain add-on behavior.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| mozilla | firefox | < 10.0.10 | 10.0.10 |
| mozilla | firefox | < 16.0.2 | 16.0.2 |
| mozilla | seamonkey | < 2.13.2 | 2.13.2 |
| mozilla | thunderbird | < 16.0.2 | 16.0.2 |
| mozilla | thunderbird_esr | < 10.0.10 | 10.0.10 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2012-10-30·CVSS 4.3
CVE-2012-4194 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
USN-1620-1 fixed vulnerabilities in Firefox. This update provides the
corresponding updates for Thunderbird. Please note that Thunderbird is only
affected by window.location issues through RSS feeds and extensions that
load web content.
Original advisory details:
Mariusz Mlynski and others discovered several flaws in Firefox that allowed
a remote attacker to conduct cross-site scripting (XSS) attacks.
(CVE-2012-4194, CVE-2012-4195)
Antoine Delignat-Lavaud discovered a flaw in the way Firefox handled the
Location object. If a user were tricked into opening a specially crafted
page, a remote attacker could exploit this to bypass security protections
and perform cross-origin reading of the Loca
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2012-10-26·CVSS 4.3
CVE-2012-4194 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Mariusz Mlynski and others discovered several flaws in Firefox that allowed
a remote attacker to conduct cross-site scripting (XSS) attacks.
(CVE-2012-4194, CVE-2012-4195)
Antoine Delignat-Lavaud discovered a flaw in the way Firefox handled the
Location object. If a user were tricked into opening a specially crafted
page, a remote attacker could exploit this to bypass security protections
and perform cross-origin reading of the Location object. (CVE-2012-4196)
Instructions: After a standard system update you need to restart Firefox to make all the
necessary changes.
Red Hat
Mozilla: Fixes for Location object issues (MFSA 2012-90)
vendor_redhat·2012-10-26·CVSS 4.3
CVE-2012-4195 [MEDIUM] Mozilla: Fixes for Location object issues (MFSA 2012-90)
Mozilla: Fixes for Location object issues (MFSA 2012-90)
The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 does not properly determine the calling document and principal in its return value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site, and makes it easier for remote attackers to execute arbitrary JavaScript code by leveraging certain add-on behavior.
GHSA
GHSA-44cp-4449-xfm3: The nsLocation::CheckURL function in Mozilla Firefox before 16
ghsa_unreviewed·2022-05-13
CVE-2012-4195 [MEDIUM] CWE-79 GHSA-44cp-4449-xfm3: The nsLocation::CheckURL function in Mozilla Firefox before 16
The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 does not properly determine the calling document and principal in its return value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site, and makes it easier for remote attackers to execute arbitrary JavaScript code by leveraging certain add-on behavior.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1407.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1413.htmlhttp://secunia.com/advisories/51121http://secunia.com/advisories/51123http://secunia.com/advisories/51127http://secunia.com/advisories/51144http://secunia.com/advisories/51146http://secunia.com/advisories/51147http://secunia.com/advisories/51165http://secunia.com/advisories/55318http://www.mozilla.org/security/announce/2012/mfsa2012-90.htmlhttp://www.securityfocus.com/bid/56302http://www.ubuntu.com/usn/USN-1620-1http://www.ubuntu.com/usn/USN-1620-2https://bugzilla.mozilla.org/show_bug.cgi?id=793121https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16856http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1407.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1413.htmlhttp://secunia.com/advisories/51121http://secunia.com/advisories/51123http://secunia.com/advisories/51127http://secunia.com/advisories/51144http://secunia.com/advisories/51146http://secunia.com/advisories/51147http://secunia.com/advisories/51165http://secunia.com/advisories/55318http://www.mozilla.org/security/announce/2012/mfsa2012-90.htmlhttp://www.securityfocus.com/bid/56302http://www.ubuntu.com/usn/USN-1620-1http://www.ubuntu.com/usn/USN-1620-2https://bugzilla.mozilla.org/show_bug.cgi?id=793121https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16856
2012-10-29
Published