CVE-2012-4207
Mozilla Firefox < 17.0 - XSS
Title source: ruleDescription
The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handle a ~ (tilde) character in proximity to a chunk delimiter, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document.
References (30)
... and 10 more
Scores
EPSS
0.0128
EPSS Percentile
79.4%
Details
CWE
CWE-79
Status
published
Products (28)
mozilla/firefox
< 17.0
mozilla/seamonkey
< 2.14
mozilla/thunderbird
< 17.0
mozilla/thunderbird_esr
< 10.0.11
opensuse/opensuse
opensuse/opensuse
opensuse/opensuse
suse/linux_enterprise_desktop
suse/linux_enterprise_desktop
suse/linux_enterprise_server
... and 18 more
Published
Nov 21, 2012
Tracked Since
Feb 18, 2026