Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2012-4153 | Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top" frame name-attribute value to access the location property, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a binary plugin. |
Ubuntu USN |
USN-1636-1 | Thunderbird vulnerabilities |
Ubuntu USN |
USN-1638-1 | Firefox vulnerabilities |
Mon, 21 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Mozilla firefox Esr
|
Subscriptions
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T20:28:07.601Z
Reserved: 2012-08-08T00:00:00.000Z
Link: CVE-2012-4209
No data.
Status : Modified
Published: 2012-11-21T12:55:02.180
Modified: 2026-06-16T23:44:37.383
Link: CVE-2012-4209
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD
Ubuntu USN