← Back

CVE-2012-3994

nvd nist
Published: Oct 10, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to conduct cross-site scripting (XSS) attacks via a binary plugin that uses Object.defineProperty to shadow the top object, and leverages the relationship between top.location and the location property.

Affected (22)

Show all products
4 products
Firefox
Thunderbird Esr
Thunderbird
Seamonkey
3 products
Linux Enterprise Desktop
Linux Enterprise Sdk
Linux Enterprise Server
1 product
Ubuntu Linux
4 products
Enterprise Linux Desktop
Enterprise Linux Eus
Enterprise Linux Server
Enterprise Linux Workstation
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 10.0.8
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 10.0.8
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 16.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 16.0
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.13
Configuration F
6 vulnerable
Vulnerable SoftwareAffected Versions
Suse
Version 10 sp4
Version 11 sp2
Version 10 sp4
Suse
Version 10 sp4
Version 11 sp2
Version 11 sp2
Configuration G
11 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 10.04
Version 11.04
Version 11.10
Version 12.04
Redhat
Version 5.0
Version 6.0
Version 6.3
Redhat
Version 5.0
Version 6.0
Redhat
Version 5.0
Version 6.0

References (32)

Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.