CVE-2012-4206
published 2012-11-21CVE-2012-4206: Untrusted search path vulnerability in the installer in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 on Windows allows local users to gain…
PriorityP418medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.33%
25.1th percentile
Untrusted search path vulnerability in the installer in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 on Windows allows local users to gain privileges via a Trojan horse DLL in the default downloads directory.
Affected
169 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 16.0.2 | — |
| mozilla | firefox | <= 22.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8jhp-825c-3qwx: Untrusted search path vulnerability in the installer in Mozilla Firefox before 17
ghsa_unreviewed·2022-05-17
CVE-2012-4206 [MEDIUM] GHSA-8jhp-825c-3qwx: Untrusted search path vulnerability in the installer in Mozilla Firefox before 17
Untrusted search path vulnerability in the installer in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 on Windows allows local users to gain privileges via a Trojan horse DLL in the default downloads directory.
GHSA
GHSA-wrqf-mx92-rrfq: Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in Mozilla Firefox before 23
ghsa_unreviewed·2022-05-17·CVSS 6.9
CVE-2013-1715 [MEDIUM] GHSA-wrqf-mx92-rrfq: Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in Mozilla Firefox before 23
Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in Mozilla Firefox before 23.0 on Windows allow local users to gain privileges via a Trojan horse DLL in the default downloads directory. NOTE: this issue exists because of an incomplete fix for CVE-2012-4206.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00021.htmlhttp://www.mozilla.org/security/announce/2012/mfsa2012-98.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=792106https://exchange.xforce.ibmcloud.com/vulnerabilities/80176https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16991http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00021.htmlhttp://www.mozilla.org/security/announce/2012/mfsa2012-98.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=792106https://exchange.xforce.ibmcloud.com/vulnerabilities/80176https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16991
2012-11-21
Published