CVE-2012-1966
18.07.2012, 10:26
Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not have the same context-menu restrictions for data: URLs as for javascript: URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 4.0 |
mozilla | firefox | 4.0:beta1 |
mozilla | firefox | 4.0:beta10 |
mozilla | firefox | 4.0:beta11 |
mozilla | firefox | 4.0:beta12 |
mozilla | firefox | 4.0:beta2 |
mozilla | firefox | 4.0:beta3 |
mozilla | firefox | 4.0:beta4 |
mozilla | firefox | 4.0:beta5 |
mozilla | firefox | 4.0:beta6 |
mozilla | firefox | 4.0:beta7 |
mozilla | firefox | 4.0:beta8 |
mozilla | firefox | 4.0:beta9 |
mozilla | firefox | 4.0.1 |
mozilla | firefox | 5.0 |
mozilla | firefox | 5.0.1 |
mozilla | firefox | 6.0 |
mozilla | firefox | 6.0.1 |
mozilla | firefox | 6.0.2 |
mozilla | firefox | 7.0 |
mozilla | firefox | 7.0.1 |
mozilla | firefox | 8.0 |
mozilla | firefox | 8.0.1 |
mozilla | firefox | 9.0 |
mozilla | firefox | 9.0.1 |
mozilla | firefox | 11.0 |
mozilla | firefox | 12.0 |
mozilla | firefox | 12.0:beta6 |
mozilla | firefox | 13.0 |
mozilla | firefox | 10.0 |
mozilla | firefox | 10.0.1 |
mozilla | firefox | 10.0.2 |
mozilla | firefox | 10.0.3 |
mozilla | firefox | 10.0.4 |
mozilla | firefox | 10.0.5 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||||||
seamonkey |
| ||||||||||||||||
thunderbird |
| ||||||||||||||||
xulrunner-1.9.2 |
| ||||||||||||||||
xulrunner-2.0 |
|
Common Weakness Enumeration
References