First published: Wed Jul 18 2012(Updated: )
Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not properly establish the security context of a feed: URL, which allows remote attackers to bypass unspecified cross-site scripting (XSS) protection mechanisms via a feed:javascript: URL.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | =4.0 | |
Firefox | =4.0-beta1 | |
Firefox | =4.0-beta10 | |
Firefox | =4.0-beta11 | |
Firefox | =4.0-beta12 | |
Firefox | =4.0-beta2 | |
Firefox | =4.0-beta3 | |
Firefox | =4.0-beta4 | |
Firefox | =4.0-beta5 | |
Firefox | =4.0-beta6 | |
Firefox | =4.0-beta7 | |
Firefox | =4.0-beta8 | |
Firefox | =4.0-beta9 | |
Firefox | =4.0.1 | |
Firefox | =5.0 | |
Firefox | =5.0.1 | |
Firefox | =6.0 | |
Firefox | =6.0.1 | |
Firefox | =6.0.2 | |
Firefox | =7.0 | |
Firefox | =7.0.1 | |
Firefox | =8.0 | |
Firefox | =8.0.1 | |
Firefox | =9.0 | |
Firefox | =9.0.1 | |
Firefox | =11.0 | |
Firefox | =12.0 | |
Firefox | =12.0-beta6 | |
Firefox | =13.0 | |
Firefox | =10.0 | |
Firefox | =10.0.1 | |
Firefox | =10.0.2 | |
Firefox | =10.0.3 | |
Firefox | =10.0.4 | |
Firefox | =10.0.5 | |
Firefox ESR | =10.0 | |
Firefox ESR | =10.0.1 | |
Firefox ESR | =10.0.2 | |
Firefox ESR | =10.0.3 | |
Firefox ESR | =10.0.4 | |
Firefox ESR | =10.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1965 has been classified as a medium severity vulnerability.
To fix CVE-2012-1965, upgrade to Firefox version 13.0 or later or Firefox ESR 10.0.6 or later.
CVE-2012-1965 is a cross-site scripting (XSS) vulnerability related to the handling of feed: URLs in Mozilla Firefox.
CVE-2012-1965 affects Mozilla Firefox versions 4.x through 13.0 and Firefox ESR versions before 10.0.6.
Yes, CVE-2012-1965 can be exploited by remote attackers to bypass XSS protections.