CVE-2012-5837
Mozilla Firefox < 16.0.2 - Code Injection
Title source: ruleDescription
The Web Developer Toolbar in Mozilla Firefox before 17.0 executes script with chrome privileges, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
References (16)
Scores
EPSS
0.0143
EPSS Percentile
80.5%
Details
CWE
CWE-94
CWE-79
Status
published
Products (50)
mozilla/firefox
mozilla/firefox
mozilla/firefox
< 16.0.2
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
... and 40 more
Published
Nov 21, 2012
Tracked Since
Feb 18, 2026