CVE-2012-4207Cross-site Scripting in Mozilla Firefox

Severity
4.3MEDIUMNVD
EPSS
1.3%
top 20.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 21
Latest updateMay 17

Description

The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handle a ~ (tilde) character in proximity to a chunk delimiter, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages11 packages

NVDmozilla/firefox10.010.0.11+1
NVDmozilla/thunderbird_esr10.010.0.11
NVDmozilla/seamonkey< 2.14
NVDopensuse/opensuse11.4, 12.1, 12.2+2

Also affects: Debian Linux 6.0, 7.0, Ubuntu Linux 10.04, 11.10, 12.04, 12.10, Enterprise Linux 6.3

Patches

🔴Vulnerability Details

3
GHSA
Cross-site scripting in yui 2.4.02022-05-17
GHSA
GHSA-jprg-6jgr-c6j9: The HZ-GB-2312 character-set implementation in Mozilla Firefox before 172022-05-13
CVEList
CVE-2012-4207: The HZ-GB-2312 character-set implementation in Mozilla Firefox before 172012-11-21

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2012-11-21
Ubuntu
Thunderbird vulnerabilities2012-11-21
Red Hat
Mozilla: Improper character decoding in HZ-GB-2312 charset (MFSA 2012-101)2012-11-20

💬Community

1
Bugzilla
CVE-2012-4207 Mozilla: Improper character decoding in HZ-GB-2312 charset (MFSA 2012-101)2012-11-17
CVE-2012-4207 — Cross-site Scripting in Mozilla Firefox | cvebase