CVE-2012-4201 describes a cross-site scripting (XSS) vulnerability in Mozilla Firefox, Thunderbird, and SeaMonkey versions prior to 17.0 (and ESR 10.x before 10.0.11). This flaw arises from an incorrect context used by the evalInSandbox implementation when handling JavaScript code that modifies the location.href property, allowing sandboxed add-ons to be leveraged for XSS attacks or arbitrary file reading. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity and a potential impact on integrity (partial). While it could lead to XSS or file reading, it does not affect confidentiality or availability. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The CVE has received minimal community discussion and media coverage, suggesting a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
>= 10.0, < 10.0.11CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 2.14CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* | ||
< 17.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
>= 10.0, < 10.0.11CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.