CVE-2012-4205

Mozilla Firefox/Thunderbird <17.0, SeaMonkey <2.14 - CSRF via XMLHttpRequest in Sandboxed Add-ons

Title source: llm
STIX 2.1

Description

Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XMLHttpRequest objects created in sandboxes, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks or obtain sensitive information by leveraging a sandboxed add-on.

References (20)

Core 20
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=779821
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1638-3
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51370
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1638-2
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2012-11/msg00093.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1636-1
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00022.html
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51434
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2012-11/msg00090.html
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51439
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51440
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1638-1
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00021.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2012-11/msg00092.html
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51381
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51369
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/80175
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/56621

Scores

EPSS 0.0080
EPSS Percentile 74.2%

Details

CWE
CWE-352
Status published
Products (15)
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 11.10
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 12.10
mozilla/firefox < 17.0
mozilla/seamonkey < 2.14
mozilla/thunderbird < 17.0
opensuse/opensuse 11.4
opensuse/opensuse 12.1
opensuse/opensuse 12.2
... and 5 more
Published Nov 21, 2012
Tracked Since Feb 18, 2026