CVE-2012-3978
Last modified
CVE-2012-3978 is a vulnerability of currently unknown severity. The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 does not properly follow the security model of the location object, which allows remote attackers to bypass intended content-loading restrictions or possibly have unspecified other impact via vectors involving chrome code.. EPSS estimates a 2.30% chance of exploitation in the next 30 days.
Description
The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 does not properly follow the security model of the location object, which allows remote attackers to bypass intended content-loading restrictions or possibly have unspecified other impact via vectors involving chrome code.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 10.0 |
| Mozilla | Firefox | 10.0.1 |
| Mozilla | Firefox | 10.0.2 |
| Mozilla | Firefox | 10.0.3 |
| Mozilla | Firefox | 10.0.4 |
| Mozilla | Firefox | 10.0.5 |
| Mozilla | Firefox | 10.0.6 |
| Mozilla | Thunderbird Esr | 10.0 |
| Mozilla | Thunderbird Esr | 10.0.1 |
| Mozilla | Thunderbird Esr | 10.0.2 |
| Mozilla | Thunderbird Esr | 10.0.3 |
| Mozilla | Thunderbird Esr | 10.0.4 |
| Mozilla | Thunderbird Esr | 10.0.5 |
| Mozilla | Thunderbird Esr | 10.0.6 |
| Mozilla | Firefox | <= 14.0 |
| Mozilla | Firefox | 1.0 |
| Mozilla | Firefox | 1.0.1 |
| Mozilla | Firefox | 1.0.2 |
| Mozilla | Firefox | 1.0.3 |
| Mozilla | Firefox | 1.0.4 |
| Mozilla | Firefox | 1.0.5 |
| Mozilla | Firefox | 1.0.6 |
| Mozilla | Firefox | 1.0.7 |
| Mozilla | Firefox | 1.0.8 |
| Mozilla | Firefox | 1.4.1 |
| Mozilla | Firefox | 1.5 |
| Mozilla | Firefox | 1.5.0.1 |
| Mozilla | Firefox | 1.5.0.2 |
| Mozilla | Firefox | 1.5.0.3 |
| Mozilla | Firefox | 1.5.0.4 |
| Mozilla | Firefox | 1.5.0.5 |
| Mozilla | Firefox | 1.5.0.6 |
| Mozilla | Firefox | 1.5.0.7 |
| Mozilla | Firefox | 1.5.0.8 |
| Mozilla | Firefox | 1.5.0.9 |
| Mozilla | Firefox | 1.5.0.10 |
| Mozilla | Firefox | 1.5.0.11 |
| Mozilla | Firefox | 1.5.0.12 |
| Mozilla | Firefox | 1.5.1 |
| Mozilla | Firefox | 1.5.2 |
| Mozilla | Firefox | 1.5.3 |
| Mozilla | Firefox | 1.5.4 |
| Mozilla | Firefox | 1.5.5 |
| Mozilla | Firefox | 1.5.6 |
| Mozilla | Firefox | 1.5.7 |
| Mozilla | Firefox | 1.5.8 |
| Mozilla | Firefox | 1.8 |
| Mozilla | Firefox | 2.0 |
| Mozilla | Firefox | 2.0.0.1 |
| Mozilla | Firefox | 2.0.0.2 |
Showing 50 of 275 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-3978?
How severe is CVE-2012-3978?
How do I fix CVE-2012-3978?
Are you affected by CVE-2012-3978?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
