CVE-2012-5837

Mozilla Firefox < 16.0.2 - Code Injection

Title source: rule

Description

The Web Developer Toolbar in Mozilla Firefox before 17.0 executes script with chrome privileges, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.

Scores

EPSS 0.0143
EPSS Percentile 80.5%

Details

CWE
CWE-94 CWE-79
Status published
Products (50)
mozilla/firefox
mozilla/firefox
mozilla/firefox < 16.0.2
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
... and 40 more
Published Nov 21, 2012
Tracked Since Feb 18, 2026