CVE-2012-3993
Firefox 5.0 - 15.0.1 __exposedProps__ XCS Code Execution
Title source: metasploitDescription
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not properly interact with failures of InstallTrigger methods, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site, related to an "XrayWrapper pollution" issue.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubylocalmultiple
https://www.exploit-db.com/exploits/30474
metasploit
WORKING POC
EXCELLENT
by Mariusz Mlynski, moz_bug_r_a4, joev · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/firefox_proto_crmfrequest.rb
References (17)
Scores
EPSS
0.8084
EPSS Percentile
99.2%
Details
CWE
CWE-269
Status
published
Products (47)
mozilla/firefox
10.0
mozilla/firefox
10.0.1
mozilla/firefox
10.0.2
mozilla/firefox
10.0.3
mozilla/firefox
10.0.4
mozilla/firefox
10.0.5
mozilla/firefox
10.0.6
mozilla/firefox
10.0.7
mozilla/firefox
1.0 (2 CPE variants)
mozilla/firefox
1.0.1
... and 37 more
Published
Oct 10, 2012
Tracked Since
Feb 18, 2026