CVE-2012-1965
Mozilla Firefox - XSS
Title source: ruleDescription
Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not properly establish the security context of a feed: URL, which allows remote attackers to bypass unspecified cross-site scripting (XSS) protection mechanisms via a feed:javascript: URL.
References (16)
Scores
EPSS
0.0122
EPSS Percentile
78.8%
Classification
CWE
CWE-79
Status
published
Affected Products (36)
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
... and 21 more
Timeline
Published
Jul 18, 2012
Tracked Since
Feb 18, 2026