Lucene search

K
nvd[email protected]NVD:CVE-2012-3992
HistoryOct 10, 2012 - 5:55 p.m.

CVE-2012-3992

2012-10-1017:55:02
CWE-79
web.nvd.nist.gov

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

7.9 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.7%

Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage history data, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive POST content via vectors involving a location.hash write operation and history navigation that triggers the loading of a URL into the history object.

Affected configurations

NVD
Node
mozillafirefox_esrRange<10.0.8
Node
mozillathunderbird_esrRange<10.0.8
Node
mozillafirefoxRange<16.0
Node
mozillathunderbirdRange<16.0
Node
mozillaseamonkeyRange<2.13
Node
canonicalubuntu_linuxMatch10.04-
OR
canonicalubuntu_linuxMatch11.04
OR
canonicalubuntu_linuxMatch11.10
OR
canonicalubuntu_linuxMatch12.04esm
OR
redhatenterprise_linux_desktopMatch5.0
OR
redhatenterprise_linux_desktopMatch6.0
OR
redhatenterprise_linux_eusMatch6.3
OR
redhatenterprise_linux_serverMatch5.0
OR
redhatenterprise_linux_serverMatch6.0
OR
redhatenterprise_linux_workstationMatch5.0
OR
redhatenterprise_linux_workstationMatch6.0
Node
suselinux_enterprise_desktopMatch10sp4
OR
suselinux_enterprise_desktopMatch11sp3
OR
suselinux_enterprise_sdkMatch10sp4
OR
suselinux_enterprise_serverMatch10sp4
OR
suselinux_enterprise_serverMatch11sp3
OR
suselinux_enterprise_serverMatch11sp3vmware

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

7.9 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.7%