CVE-2012-3985

Mozilla Firefox < 16.0, Thunderbird < 16.0, SeaMonkey < 2.13 - XSS via HTML5 Same Origin Bypass

Title source: llm
STIX 2.1

Description

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.

References (11)

Core 11
Core References
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50904
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50984
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50935
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50856
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/86106
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50892
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=655649
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1611-1

Scores

EPSS 0.0092
EPSS Percentile 76.3%

Details

CWE
CWE-79
Status published
Products (11)
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 11.04
canonical/ubuntu_linux 11.10
canonical/ubuntu_linux 12.04
mozilla/firefox < 16.0
mozilla/seamonkey < 2.13
mozilla/thunderbird < 16.0
suse/linux_enterprise_desktop 10 sp4
suse/linux_enterprise_desktop 11 sp2
suse/linux_enterprise_server 10 sp4
... and 1 more
Published Oct 10, 2012
Tracked Since Feb 18, 2026