CVE-2012-3985
Mozilla Firefox < 16.0 - XSS
Title source: ruleDescription
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.
References (11)
Scores
EPSS
0.0092
EPSS Percentile
75.8%
Details
CWE
CWE-79
Status
published
Products (13)
mozilla/firefox
< 16.0
mozilla/seamonkey
< 2.13
mozilla/thunderbird
< 16.0
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
suse/linux_enterprise_desktop
suse/linux_enterprise_desktop
suse/linux_enterprise_server
... and 3 more
Published
Oct 10, 2012
Tracked Since
Feb 18, 2026