CVE-2012-1959: Medium severity firefox vulnerability
Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not consider the presence of same-compartment security wrappers (SCSW) during the cross-compartment wrapping of objects, which allows remote attackers to bypass intended XBL access restrictions via crafted content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1959?
CVE-2012-1959 has been classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2012-1959?
To fix CVE-2012-1959, update Firefox, Thunderbird, or SeaMonkey to the latest version available.
Which versions are affected by CVE-2012-1959?
CVE-2012-1959 affects Mozilla Firefox versions 4.x through 13.0, Thunderbird versions 5.0 through 13.0, and SeaMonkey before version 2.11.
What types of applications does CVE-2012-1959 impact?
CVE-2012-1959 impacts Mozilla Firefox, Thunderbird, and SeaMonkey applications.
Is there a workaround for CVE-2012-1959 while waiting for the fix?
There is no official workaround for CVE-2012-1959, and it is recommended to apply the update as soon as possible.