CVE-2012-1966: XSS
Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not have the same context-menu restrictions for data: URLs as for javascript: URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1966?
CVE-2012-1966 has a moderate severity rating as it allows for cross-site scripting (XSS) attacks.
How do I fix CVE-2012-1966?
To fix CVE-2012-1966, update Mozilla Firefox to version 13.0 or later, or apply any available patches for affected versions.
What versions of Firefox are affected by CVE-2012-1966?
CVE-2012-1966 affects Mozilla Firefox versions 4.x through 13.0 and Firefox ESR 10.x before 10.0.6.
What is the impact of CVE-2012-1966?
The impact of CVE-2012-1966 allows remote attackers to execute arbitrary JavaScript code via crafted data URLs, leading to potential security breaches.
Can CVE-2012-1966 exploit my web applications?
Yes, CVE-2012-1966 can be exploited to conduct XSS attacks on web applications that allow the use of manipulated data URLs.