Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-1956
HistoryAug 29, 2012 - 12:00 a.m.

CVE-2012-1956

2012-08-2900:00:00
ubuntu.com
ubuntu.com
10

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

71.3%

Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before
2.12 do not prevent use of the Object.defineProperty method to shadow the
location object (aka window.location), which makes it easier for remote
attackers to conduct cross-site scripting (XSS) attacks via vectors
involving a plugin.

OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchfirefox< 15.0+build1-0ubuntu0.10.04.1UNKNOWN
ubuntu11.04noarchfirefox< 15.0+build1-0ubuntu0.11.04.2UNKNOWN
ubuntu11.10noarchfirefox< 15.0+build1-0ubuntu0.11.10.1UNKNOWN
ubuntu12.04noarchfirefox< 15.0+build1-0ubuntu0.12.04.1UNKNOWN
ubuntu12.10noarchfirefox< 15.0+build1-0ubuntu1UNKNOWN
ubuntu13.04noarchfirefox< 15.0+build1-0ubuntu1UNKNOWN
ubuntu13.10noarchfirefox< 15.0+build1-0ubuntu1UNKNOWN
ubuntu10.04noarchthunderbird< 15.0+build1-0ubuntu0.10.04.1UNKNOWN
ubuntu11.04noarchthunderbird< 15.0+build1-0ubuntu0.11.04.1UNKNOWN
ubuntu11.10noarchthunderbird< 15.0+build1-0ubuntu0.11.10.1UNKNOWN
Rows per page:
1-10 of 141

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

71.3%