CVE-2012-1965

Mozilla Firefox - XSS

Title source: rule

Description

Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not properly establish the security context of a feed: URL, which allows remote attackers to bypass unspecified cross-site scripting (XSS) protection mechanisms via a feed:javascript: URL.

Scores

EPSS 0.0122
EPSS Percentile 78.8%

Classification

CWE
CWE-79
Status published

Affected Products (36)

mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
... and 21 more

Timeline

Published Jul 18, 2012
Tracked Since Feb 18, 2026