CVE-2012-4195 describes a cross-site scripting (XSS) vulnerability in the nsLocation::CheckURL function affecting Mozilla Firefox, Thunderbird, and SeaMonkey versions prior to their respective patches. This flaw allows remote attackers to conduct XSS attacks and execute arbitrary JavaScript code through crafted websites or by leveraging specific add-on behaviors. With a CVSS score of 4.3 (medium severity), it requires user interaction (medium attack complexity) and primarily impacts integrity, allowing for partial information disclosure or manipulation. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.10CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 16.0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 2.13.2CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* | ||
< 16.0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
< 10.0.10CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.