← Zuruck zu CVEs
CVE-2012-3978
N/ABeschreibung
The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 does not properly follow the security model of the location object, which allows remote attackers to bypass intended content-loading restrictions or possibly have unspecified other impact via vectors involving chrome code.
CVE Details
CVSS v3.1 BewertungN/A
Veroffentlicht8/29/2012
Zuletzt geandert4/29/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
mozilla:firefoxmozilla:seamonkeymozilla:thunderbirdmozilla:thunderbird_esr
Schwachen (CWE)
CWE-264
Referenzen
http://rhn.redhat.com/errata/RHSA-2012-1210.html(cve@mitre.org)
http://rhn.redhat.com/errata/RHSA-2012-1211.html(cve@mitre.org)
http://www.debian.org/security/2012/dsa-2553(cve@mitre.org)
http://www.debian.org/security/2012/dsa-2554(cve@mitre.org)
http://www.debian.org/security/2012/dsa-2556(cve@mitre.org)
http://www.securityfocus.com/bid/55306(cve@mitre.org)
http://www.ubuntu.com/usn/USN-1548-1(cve@mitre.org)
http://www.ubuntu.com/usn/USN-1548-2(cve@mitre.org)
http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf(cve@mitre.org)
https://bugzilla.mozilla.org/show_bug.cgi?id=770429(cve@mitre.org)
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16923(cve@mitre.org)
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00028.html(af854a3a-2127-422b-91ae-364da2661108)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.html(af854a3a-2127-422b-91ae-364da2661108)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2012-1210.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2012-1211.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2012/dsa-2553(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2012/dsa-2554(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2012/dsa-2556(af854a3a-2127-422b-91ae-364da2661108)
http://www.mozilla.org/security/announce/2012/mfsa2012-70.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/55306(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-1548-1(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-1548-2(af854a3a-2127-422b-91ae-364da2661108)
http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.mozilla.org/show_bug.cgi?id=770429(af854a3a-2127-422b-91ae-364da2661108)
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16923(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.