CVE-2012-1963: Medium severity firefox vulnerability
The Content Security Policy (CSP) functionality in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly restrict the strings placed into the blocked-uri parameter of a violation report, which allows remote web servers to capture OpenID credentials and OAuth 2.0 access tokens by triggering a violation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1963?
CVE-2012-1963 is classified as a moderate severity vulnerability.
How do I fix CVE-2012-1963?
To fix CVE-2012-1963, update your Mozilla Firefox, Thunderbird, or SeaMonkey to the latest version.
Which software is affected by CVE-2012-1963?
CVE-2012-1963 affects Mozilla Firefox versions 4.x through 13.0, Thunderbird versions 5.0 through 13.0, and SeaMonkey versions before 2.11.
When was CVE-2012-1963 disclosed?
CVE-2012-1963 was disclosed in July 2012.
What type of vulnerability is CVE-2012-1963?
CVE-2012-1963 is a vulnerability related to the Content Security Policy functionality.