6.8

CVE-2012-0458

Exploit

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict setting the home page through the dragging of a URL to the home button, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a javascript: URL that is later interpreted in the about:sessionrestore context.

Data is provided by the National Vulnerability Database (NVD)
MozillaFirefox Version <= 3.6.27
MozillaFirefox Version > 4.0 <= 10.0
MozillaFirefox Version10.0
MozillaFirefox Version10.0.1
MozillaFirefox Version10.0.2
MozillaThunderbird Version >= 1.0 <= 3.1.19
MozillaThunderbird Version > 5.0 <= 10.0
MozillaThunderbird Esr Version10.0
MozillaThunderbird Esr Version10.0.1
MozillaThunderbird Esr Version10.0.2
MozillaSeamonkey Version-
MozillaSeamonkey Version1.0
MozillaSeamonkey Version1.0 Updatealpha
MozillaSeamonkey Version1.0 Updatebeta
MozillaSeamonkey Version1.0.1
MozillaSeamonkey Version1.0.2
MozillaSeamonkey Version1.0.3
MozillaSeamonkey Version1.0.4
MozillaSeamonkey Version1.0.5
MozillaSeamonkey Version1.0.6
MozillaSeamonkey Version1.0.7
MozillaSeamonkey Version1.0.8
MozillaSeamonkey Version1.0.9
MozillaSeamonkey Version1.1
MozillaSeamonkey Version1.1 Updatealpha
MozillaSeamonkey Version1.1 Updatebeta
MozillaSeamonkey Version1.1.1
MozillaSeamonkey Version1.1.2
MozillaSeamonkey Version1.1.3
MozillaSeamonkey Version1.1.4
MozillaSeamonkey Version1.1.5
MozillaSeamonkey Version1.1.6
MozillaSeamonkey Version1.1.7
MozillaSeamonkey Version1.1.8
MozillaSeamonkey Version1.1.9
MozillaSeamonkey Version1.1.10
MozillaSeamonkey Version1.1.11
MozillaSeamonkey Version1.1.12
MozillaSeamonkey Version1.1.13
MozillaSeamonkey Version1.1.14
MozillaSeamonkey Version1.1.15
MozillaSeamonkey Version1.1.16
MozillaSeamonkey Version1.1.17
MozillaSeamonkey Version1.1.18
MozillaSeamonkey Version1.1.19
MozillaSeamonkey Version1.5.0.8
MozillaSeamonkey Version1.5.0.9
MozillaSeamonkey Version1.5.0.10
MozillaSeamonkey Version2.0
MozillaSeamonkey Version2.0 Updatealpha_1
MozillaSeamonkey Version2.0 Updatealpha_2
MozillaSeamonkey Version2.0 Updatealpha_3
MozillaSeamonkey Version2.0 Updatebeta_1
MozillaSeamonkey Version2.0 Updatebeta_2
MozillaSeamonkey Version2.0 Updaterc1
MozillaSeamonkey Version2.0 Updaterc2
MozillaSeamonkey Version2.0.1
MozillaSeamonkey Version2.0.2
MozillaSeamonkey Version2.0.3
MozillaSeamonkey Version2.0.4
MozillaSeamonkey Version2.0.5
MozillaSeamonkey Version2.0.6
MozillaSeamonkey Version2.0.7
MozillaSeamonkey Version2.0.8
MozillaSeamonkey Version2.0.9
MozillaSeamonkey Version2.0.10
MozillaSeamonkey Version2.0.11
MozillaSeamonkey Version2.0.12
MozillaSeamonkey Version2.0.13
MozillaSeamonkey Version2.0.14
MozillaSeamonkey Version2.1
MozillaSeamonkey Version2.1 Updatealpha1
MozillaSeamonkey Version2.1 Updatealpha2
MozillaSeamonkey Version2.1 Updatealpha3
MozillaSeamonkey Version2.1 Updatebeta1
MozillaSeamonkey Version2.1 Updatebeta2
MozillaSeamonkey Version2.1 Updatebeta3
MozillaSeamonkey Version2.1 Updaterc1
MozillaSeamonkey Version2.1 Updaterc2
MozillaSeamonkey Version2.2
MozillaSeamonkey Version2.2 Updatebeta1
MozillaSeamonkey Version2.2 Updatebeta2
MozillaSeamonkey Version2.2 Updatebeta3
MozillaSeamonkey Version2.3
MozillaSeamonkey Version2.3 Updatebeta1
MozillaSeamonkey Version2.3 Updatebeta2
MozillaSeamonkey Version2.3 Updatebeta3
MozillaSeamonkey Version2.3.1
MozillaSeamonkey Version2.3.2
MozillaSeamonkey Version2.3.3
MozillaSeamonkey Version2.4
MozillaSeamonkey Version2.4 Updatebeta1
MozillaSeamonkey Version2.4 Updatebeta2
MozillaSeamonkey Version2.4 Updatebeta3
MozillaSeamonkey Version2.4.1
MozillaSeamonkey Version2.5
MozillaSeamonkey Version2.5 Updatebeta1
MozillaSeamonkey Version2.5 Updatebeta2
MozillaSeamonkey Version2.5 Updatebeta3
MozillaSeamonkey Version2.5 Updatebeta4
MozillaSeamonkey Version2.6
MozillaSeamonkey Version2.6 Updatebeta1
MozillaSeamonkey Version2.6 Updatebeta2
MozillaSeamonkey Version2.6 Updatebeta3
MozillaSeamonkey Version2.6 Updatebeta4
MozillaSeamonkey Version2.6.1
MozillaSeamonkey Version2.7
MozillaSeamonkey Version2.7 Updatebeta1
MozillaSeamonkey Version2.7 Updatebeta2
MozillaSeamonkey Version2.7 Updatebeta3
MozillaSeamonkey Version2.7 Updatebeta4
MozillaSeamonkey Version2.7 Updatebeta5
MozillaSeamonkey Version2.7.1
MozillaSeamonkey Version2.7.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.78% 0.855
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
https://bugzilla.mozilla.org/show_bug.cgi?id=718203
Vendor Advisory
Exploit
Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=723808
Patch
Vendor Advisory
Issue Tracking