Executive Summary

Informations
NameCVE-2012-0446First vendor Publication2012-02-01
VendorCveLast vendor Modification2012-12-18

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Cvss Base Score4.3Attack RangeNetwork
Cvss Impact Score2.9Attack ComplexityMedium
Cvss Expoit Score8.6AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to inject arbitrary web script or HTML via a (1) web page or (2) Firefox extension, related to improper enforcement of XPConnect security restrictions for frame scripts that call untrusted objects.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0446

CWE : Common Weakness Enumeration

idName
CWE-79Failure to Preserve Web Page Structure ('Cross-site Scripting')

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:14304
 
Oval ID: oval:org.mitre.oval:def:14304
Title: Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to inject arbitrary web script or HTML via a (1) web page or (2) Firefox extension, related to improper enforcement of XPConnect security restrictions for frame scripts that call untrusted objects.
Description: Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to inject arbitrary web script or HTML via a (1) web page or (2) Firefox extension, related to improper enforcement of XPConnect security restrictions for frame scripts that call untrusted objects.
Family: windows Class: vulnerability
Reference(s): CVE-2012-0446
Version: 7
Platform(s): Microsoft Windows 7
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows Server 2003
Microsoft Windows XP
Microsoft Windows 2000
Product(s): Mozilla Firefox
Mozilla Thunderbird
Mozilla Seamonkey
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application23
Application96
Application7

Internal Sources (Detail)

SourceUrl
BIDhttp://www.securityfocus.com/bid/51752
CONFIRMhttp://www.mozilla.org/security/announce/2012/mfsa2012-05.html
https://bugzilla.mozilla.org/show_bug.cgi?id=705651
MANDRIVAhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:013
SECUNIAhttp://secunia.com/advisories/49055
SUSEhttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00011.html
XFhttp://xforce.iss.net/xforce/xfdb/72837

Alert History

If you want to see full details history, please login or register.
0
1
DateInformations
2013-05-10 22:32:30
  • Multiple Updates
2012-12-19 13:24:04
  • Multiple Updates