CVE-2012-1965

Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not properly establish the security context of a feed: URL, which allows remote attackers to bypass unspecified cross-site scripting (XSS) protection mechanisms via a feed:javascript: URL.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00013.html
http://osvdb.org/84012
http://rhn.redhat.com/errata/RHSA-2012-1088.html
http://secunia.com/advisories/49965
http://secunia.com/advisories/49972
http://secunia.com/advisories/49979
http://secunia.com/advisories/49992
http://www.mozilla.org/security/announce/2012/mfsa2012-55.html Vendor Advisory
http://www.securityfocus.com/bid/54579
http://www.securitytracker.com/id?1027256
http://www.ubuntu.com/usn/USN-1509-1
http://www.ubuntu.com/usn/USN-1509-2
https://bugzilla.mozilla.org/show_bug.cgi?id=758990
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17001
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00013.html
http://osvdb.org/84012
http://rhn.redhat.com/errata/RHSA-2012-1088.html
http://secunia.com/advisories/49965
http://secunia.com/advisories/49972
http://secunia.com/advisories/49979
http://secunia.com/advisories/49992
http://www.mozilla.org/security/announce/2012/mfsa2012-55.html Vendor Advisory
http://www.securityfocus.com/bid/54579
http://www.securitytracker.com/id?1027256
http://www.ubuntu.com/usn/USN-1509-1
http://www.ubuntu.com/usn/USN-1509-2
https://bugzilla.mozilla.org/show_bug.cgi?id=758990
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17001
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:4.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:4.0:beta10:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:4.0:beta11:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:4.0:beta12:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:4.0:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:4.0:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:4.0:beta4:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:4.0:beta5:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:4.0:beta6:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:4.0:beta7:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:4.0:beta8:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:4.0:beta9:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:5.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:6.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:7.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:8.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:8.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:9.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:9.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:11.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:12.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:12.0:beta6:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:13.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:mozilla:firefox:10.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:10.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:10.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:10.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:10.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:10.0.5:*:*:*:*:*:*:*

History

21 Nov 2024, 01:38

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00011.html - () http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00011.html -
References () http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00012.html - () http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00012.html -
References () http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00013.html - () http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00013.html -
References () http://osvdb.org/84012 - () http://osvdb.org/84012 -
References () http://rhn.redhat.com/errata/RHSA-2012-1088.html - () http://rhn.redhat.com/errata/RHSA-2012-1088.html -
References () http://secunia.com/advisories/49965 - () http://secunia.com/advisories/49965 -
References () http://secunia.com/advisories/49972 - () http://secunia.com/advisories/49972 -
References () http://secunia.com/advisories/49979 - () http://secunia.com/advisories/49979 -
References () http://secunia.com/advisories/49992 - () http://secunia.com/advisories/49992 -
References () http://www.mozilla.org/security/announce/2012/mfsa2012-55.html - Vendor Advisory () http://www.mozilla.org/security/announce/2012/mfsa2012-55.html - Vendor Advisory
References () http://www.securityfocus.com/bid/54579 - () http://www.securityfocus.com/bid/54579 -
References () http://www.securitytracker.com/id?1027256 - () http://www.securitytracker.com/id?1027256 -
References () http://www.ubuntu.com/usn/USN-1509-1 - () http://www.ubuntu.com/usn/USN-1509-1 -
References () http://www.ubuntu.com/usn/USN-1509-2 - () http://www.ubuntu.com/usn/USN-1509-2 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=758990 - () https://bugzilla.mozilla.org/show_bug.cgi?id=758990 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17001 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17001 -

21 Oct 2024, 13:55

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox_esr:10.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:10.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:10.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:10.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:10.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:10.0.2:*:*:*:*:*:*:*

21 Oct 2024, 13:11

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox_esr:10.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:10.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:10.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:10.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:10.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:10.0.4:*:*:*:*:*:*:*

Information

Published : 2012-07-18 10:26

Updated : 2024-11-21 01:38


NVD link : CVE-2012-1965

Mitre link : CVE-2012-1965

CVE.ORG link : CVE-2012-1965


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')