CVE-2012-0455

CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.34 % (72th)
0.34% Progress
Affected Products 5
Advisories 10

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web page, related to a "DragAndDropJacking" issue.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2012-03-14 19:55:01
(12 years ago)
Updated Date
2018-01-18 02:29:04
(6 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 3.6.27 and prior versions cpe:2.3:a:mozilla:firefox <= 3.6.27

Configuration #2

    CPE23 From Up To
  Mozilla Firefox 4.0 cpe:2.3:a:mozilla:firefox:4.0
  Mozilla Firefox 4.0 Beta1 cpe:2.3:a:mozilla:firefox:4.0:beta1
  Mozilla Firefox 4.0 Beta10 cpe:2.3:a:mozilla:firefox:4.0:beta10
  Mozilla Firefox 4.0 Beta11 cpe:2.3:a:mozilla:firefox:4.0:beta11
  Mozilla Firefox 4.0 Beta12 cpe:2.3:a:mozilla:firefox:4.0:beta12
  Mozilla Firefox 4.0 Beta2 cpe:2.3:a:mozilla:firefox:4.0:beta2
  Mozilla Firefox 4.0 Beta3 cpe:2.3:a:mozilla:firefox:4.0:beta3
  Mozilla Firefox 4.0 Beta4 cpe:2.3:a:mozilla:firefox:4.0:beta4
  Mozilla Firefox 4.0 Beta5 cpe:2.3:a:mozilla:firefox:4.0:beta5
  Mozilla Firefox 4.0 Beta6 cpe:2.3:a:mozilla:firefox:4.0:beta6
  Mozilla Firefox 4.0 Beta7 cpe:2.3:a:mozilla:firefox:4.0:beta7
  Mozilla Firefox 4.0 Beta8 cpe:2.3:a:mozilla:firefox:4.0:beta8
  Mozilla Firefox 4.0 Beta9 cpe:2.3:a:mozilla:firefox:4.0:beta9
  Mozilla Firefox 4.0.1 cpe:2.3:a:mozilla:firefox:4.0.1
  Mozilla Firefox 5.0 cpe:2.3:a:mozilla:firefox:5.0
  Mozilla Firefox 5.0.1 cpe:2.3:a:mozilla:firefox:5.0.1
  Mozilla Firefox 6.0 cpe:2.3:a:mozilla:firefox:6.0
  Mozilla Firefox 6.0.1 cpe:2.3:a:mozilla:firefox:6.0.1
  Mozilla Firefox 6.0.2 cpe:2.3:a:mozilla:firefox:6.0.2
  Mozilla Firefox 7.0 cpe:2.3:a:mozilla:firefox:7.0
  Mozilla Firefox 7.0.1 cpe:2.3:a:mozilla:firefox:7.0.1
  Mozilla Firefox 8.0 cpe:2.3:a:mozilla:firefox:8.0
  Mozilla Firefox 8.0.1 cpe:2.3:a:mozilla:firefox:8.0.1
  Mozilla Firefox 9.0 cpe:2.3:a:mozilla:firefox:9.0
  Mozilla Firefox 9.0.1 cpe:2.3:a:mozilla:firefox:9.0.1

Configuration #3

    CPE23 From Up To
  Mozilla Firefox Esr 10.0 cpe:2.3:a:mozilla:firefox_esr:10.0
  Mozilla Firefox Esr 10.1 cpe:2.3:a:mozilla:firefox_esr:10.1
  Mozilla Firefox Esr 10.2 cpe:2.3:a:mozilla:firefox_esr:10.2

Configuration #4

    CPE23 From Up To
  Mozilla Thunderbird 3.1.19 and prior versions cpe:2.3:a:mozilla:thunderbird <= 3.1.19

Configuration #5

    CPE23 From Up To
  Mozilla Thunderbird 5.0 cpe:2.3:a:mozilla:thunderbird:5.0
  Mozilla Thunderbird 6.0 cpe:2.3:a:mozilla:thunderbird:6.0
  Mozilla Thunderbird 6.0.1 cpe:2.3:a:mozilla:thunderbird:6.0.1
  Mozilla Thunderbird 6.0.2 cpe:2.3:a:mozilla:thunderbird:6.0.2
  Mozilla Thunderbird 8.0 cpe:2.3:a:mozilla:thunderbird:8.0
  Mozilla Thunderbird 9.0 cpe:2.3:a:mozilla:thunderbird:9.0
  Mozilla Thunderbird 9.0.1 cpe:2.3:a:mozilla:thunderbird:9.0.1

Configuration #6

    CPE23 From Up To
  Mozilla Thunderbird Esr 10.0 cpe:2.3:a:mozilla:thunderbird_esr:10.0
  Mozilla Thunderbird Esr 10.0.1 cpe:2.3:a:mozilla:thunderbird_esr:10.0.1
  Mozilla Thunderbird Esr 10.0.2 cpe:2.3:a:mozilla:thunderbird_esr:10.0.2

Configuration #7

    CPE23 From Up To
  Mozilla Seamonkey Beta5 2.7 and prior versions cpe:2.3:a:mozilla:seamonkey::beta5 <= 2.7
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...