CVE-2012-4209
Mozilla Firefox < 17.0 - XSS
Title source: ruleDescription
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top" frame name-attribute value to access the location property, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a binary plugin.
References (25)
... and 5 more
Scores
EPSS
0.0207
EPSS Percentile
83.8%
Details
CWE
CWE-79
Status
published
Products (26)
mozilla/firefox
< 17.0
mozilla/seamonkey
< 2.14
mozilla/thunderbird
< 17.0
mozilla/thunderbird_esr
< 10.0.11
opensuse/opensuse
opensuse/opensuse
opensuse/opensuse
suse/linux_enterprise_desktop
suse/linux_enterprise_desktop
suse/linux_enterprise_server
... and 16 more
Published
Nov 21, 2012
Tracked Since
Feb 18, 2026