CVE-2012-4192

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same Origin Policy and read the properties of a Location object via a crafted web site, a related issue to CVE-2012-4193.

References

http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.html

http://secunia.com/advisories/50904

http://secunia.com/advisories/50929

http://secunia.com/advisories/50984

http://secunia.com/advisories/55318

http://www.mozilla.org/security/announce/2012/mfsa2012-89.html

http://www.thespanner.co.uk/2012/10/10/firefox-knows-what-your-friends-did-last-summer/

http://www.ubuntu.com/usn/USN-1608-1

http://www.ubuntu.com/usn/USN-1611-1

https://bugzilla.mozilla.org/show_bug.cgi?id=799952

https://exchange.xforce.ibmcloud.com/vulnerabilities/79210

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17095

Details

Source: MITRE

Published: 2012-10-12

Updated: 2017-09-19

Type: CWE-264

Risk Information

CVSS v2

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

Tenable Plugins

View all (23 total)

IDNameProductFamilySeverity
83562SUSE SLED10 / SLED11 / SLES10 / SLES11 Security Update : Mozilla Firefox (SUSE-SU-2012:1351-1)NessusSuSE Local Security Checks
critical
74779openSUSE Security Update : MozillaFirefox (openSUSE-SU-2012:1345-1)NessusSuSE Local Security Checks
critical
64133SuSE 11.2 Security Update : Mozilla Firefox (SAT Patch Number 6951)NessusSuSE Local Security Checks
critical
63402GLSA-201301-01 : Mozilla Products: Multiple vulnerabilities (BEAST)NessusGentoo Local Security Checks
critical
62592SeaMonkey < 2.13.1 Multiple VulnerabilitiesNessusWindows
critical
62591Mozilla Thunderbird < 16.0.1 Multiple VulnerabilitiesNessusWindows
critical
62590Mozilla Thunderbird 10.x < 10.0.9 Multiple VulnerabilitiesNessusWindows
high
62589Firefox < 16.0.1 Multiple VulnerabilitiesNessusWindows
critical
62588Firefox 10.x < 10.0.9 Multiple VulnerabilitiesNessusWindows
high
62587Thunderbird < 16.0.1 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
62586Thunderbird 10.x < 10.0.9 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
62585Firefox < 16.0.1 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
62584Firefox < 10.0.9 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
62573SuSE 10 Security Update : Mozilla Firefox (ZYPP Patch Number 8327)NessusSuSE Local Security Checks
critical
801325Mozilla Firefox 15.x <= 15 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801323Mozilla Thunderbird 15.x <= 15 Multiple VulnerabilitiesLog Correlation EngineSMTP Clients
high
801301Mozilla SeaMonkey 2.x < 2.13 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
6604Mozilla Thunderbird < 16.0.1 Multiple VulnerabilitiesNessus Network MonitorSMTP Clients
high
6603SeaMonkey 2.x < 2.13 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
6602Mozilla Firefox < 16.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
62548Ubuntu 10.04 LTS / 11.04 / 11.10 / 12.04 LTS : thunderbird vulnerabilities (USN-1611-1)NessusUbuntu Local Security Checks
critical
62515Ubuntu 10.04 LTS / 11.04 / 11.10 / 12.04 LTS : firefox vulnerabilities (USN-1608-1)NessusUbuntu Local Security Checks
critical
62490FreeBSD : mozilla -- multiple vulnerabilities (6e5a9afd-12d3-11e2-b47d-c8600054b392)NessusFreeBSD Local Security Checks
critical