CVE-2012-4203Mozilla Firefox vulnerability

CWE-2647 documents5 sources
Severity
6.8MEDIUMNVD
EPSS
2.4%
top 14.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 21
Latest updateMay 17

Description

The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScript code by bookmarklets, which allows user-assisted remote attackers to run arbitrary programs by leveraging a javascript: URL in a bookmark.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

NVDmozilla/firefox16.0.2+153

🔴Vulnerability Details

1
GHSA
GHSA-rfmr-q5xq-hg6g: The New Tab page in Mozilla Firefox before 172022-05-17

📋Vendor Advisories

4
Ubuntu
Firefox regressions2012-12-03
Ubuntu
Firefox vulnerabilities2012-11-21
Ubuntu
ubufox update2012-11-21
Red Hat
Mozilla: Javascript: URLs run in privileged context on New Tab page (MFSA 2012-95)2012-11-20

💬Community

1
Bugzilla
CVE-2012-4203 Mozilla: Javascript: URLs run in privileged context on New Tab page (MFSA 2012-95)2012-11-17