CVE-2012-3985

Mozilla Firefox < 16.0 - XSS

Title source: rule

Description

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.

Scores

EPSS 0.0092
EPSS Percentile 75.8%

Details

CWE
CWE-79
Status published
Products (13)
mozilla/firefox < 16.0
mozilla/seamonkey < 2.13
mozilla/thunderbird < 16.0
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
suse/linux_enterprise_desktop
suse/linux_enterprise_desktop
suse/linux_enterprise_server
... and 3 more
Published Oct 10, 2012
Tracked Since Feb 18, 2026