Back to search
CVE-2012-4203
Published: Nov 21, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScript code by bookmarklets, which allows user-assisted remote attackers to run arbitrary programs by leveraging a javascript: URL in a bookmark.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugzilla.mozilla.org/show_bug.cgi?id=765628
x_refsource_CONFIRM
USN-1638-3
vendor-advisory
x_refsource_UBUNTU
USN-1638-2
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2012:1586
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2013:0175
vendor-advisory
x_refsource_SUSE
51434
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2012:1583
vendor-advisory
x_refsource_SUSE
51439
third-party-advisory
x_refsource_SECUNIA
56623
vdb-entry
x_refsource_BID
USN-1638-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2012:1592
vendor-advisory
x_refsource_SUSE
oval:org.mitre.oval:def:16503
vdb-entry
signature
x_refsource_OVAL
51369
third-party-advisory
x_refsource_SECUNIA
http://www.mozilla.org/security/announce/2012/mfsa2012-95.html
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now