First published: Wed Aug 29 2012(Updated: )
The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 loads subresources during parsing of text/html data within an extension, which allows remote attackers to obtain sensitive information by providing crafted data to privileged extension code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <=14.0 | |
Firefox | =1.0 | |
Firefox | =1.0-preview_release | |
Firefox | =1.0.1 | |
Firefox | =1.0.2 | |
Firefox | =1.0.3 | |
Firefox | =1.0.4 | |
Firefox | =1.0.5 | |
Firefox | =1.0.6 | |
Firefox | =1.0.7 | |
Firefox | =1.0.8 | |
Firefox | =1.4.1 | |
Firefox | =1.5 | |
Firefox | =1.5-beta1 | |
Firefox | =1.5-beta2 | |
Firefox | =1.5.0.1 | |
Firefox | =1.5.0.2 | |
Firefox | =1.5.0.3 | |
Firefox | =1.5.0.4 | |
Firefox | =1.5.0.5 | |
Firefox | =1.5.0.6 | |
Firefox | =1.5.0.7 | |
Firefox | =1.5.0.8 | |
Firefox | =1.5.0.9 | |
Firefox | =1.5.0.10 | |
Firefox | =1.5.0.11 | |
Firefox | =1.5.0.12 | |
Firefox | =1.5.1 | |
Firefox | =1.5.2 | |
Firefox | =1.5.3 | |
Firefox | =1.5.4 | |
Firefox | =1.5.5 | |
Firefox | =1.5.6 | |
Firefox | =1.5.7 | |
Firefox | =1.5.8 | |
Firefox | =1.8 | |
Firefox | =2.0 | |
Firefox | =2.0.0.1 | |
Firefox | =2.0.0.2 | |
Firefox | =2.0.0.3 | |
Firefox | =2.0.0.4 | |
Firefox | =2.0.0.5 | |
Firefox | =2.0.0.6 | |
Firefox | =2.0.0.7 | |
Firefox | =2.0.0.8 | |
Firefox | =2.0.0.9 | |
Firefox | =2.0.0.10 | |
Firefox | =2.0.0.11 | |
Firefox | =2.0.0.12 | |
Firefox | =2.0.0.13 | |
Firefox | =2.0.0.14 | |
Firefox | =2.0.0.15 | |
Firefox | =2.0.0.16 | |
Firefox | =2.0.0.17 | |
Firefox | =2.0.0.18 | |
Firefox | =2.0.0.19 | |
Firefox | =2.0.0.20 | |
Firefox | =3.0 | |
Firefox | =3.0.1 | |
Firefox | =3.0.2 | |
Firefox | =3.0.3 | |
Firefox | =3.0.4 | |
Firefox | =3.0.5 | |
Firefox | =3.0.6 | |
Firefox | =3.0.7 | |
Firefox | =3.0.8 | |
Firefox | =3.0.9 | |
Firefox | =3.0.10 | |
Firefox | =3.0.11 | |
Firefox | =3.0.12 | |
Firefox | =3.0.13 | |
Firefox | =3.0.14 | |
Firefox | =3.0.15 | |
Firefox | =3.0.16 | |
Firefox | =3.0.17 | |
Firefox | =3.5 | |
Firefox | =3.5.1 | |
Firefox | =3.5.2 | |
Firefox | =3.5.3 | |
Firefox | =3.5.4 | |
Firefox | =3.5.5 | |
Firefox | =3.5.6 | |
Firefox | =3.5.7 | |
Firefox | =3.5.8 | |
Firefox | =3.5.9 | |
Firefox | =3.5.10 | |
Firefox | =3.5.11 | |
Firefox | =3.5.12 | |
Firefox | =3.5.13 | |
Firefox | =3.5.14 | |
Firefox | =3.5.15 | |
Firefox | =3.6 | |
Firefox | =3.6.2 | |
Firefox | =3.6.3 | |
Firefox | =3.6.4 | |
Firefox | =3.6.6 | |
Firefox | =3.6.7 | |
Firefox | =3.6.8 | |
Firefox | =3.6.9 | |
Firefox | =3.6.10 | |
Firefox | =3.6.11 | |
Firefox | =3.6.12 | |
Firefox | =3.6.13 | |
Firefox | =3.6.14 | |
Firefox | =3.6.15 | |
Firefox | =3.6.16 | |
Firefox | =3.6.17 | |
Firefox | =3.6.18 | |
Firefox | =3.6.19 | |
Firefox | =3.6.20 | |
Firefox | =3.6.21 | |
Firefox | =3.6.22 | |
Firefox | =3.6.23 | |
Firefox | =3.6.24 | |
Firefox | =3.6.25 | |
Firefox | =4.0 | |
Firefox | =4.0-beta1 | |
Firefox | =4.0-beta10 | |
Firefox | =4.0-beta11 | |
Firefox | =4.0-beta12 | |
Firefox | =4.0-beta2 | |
Firefox | =4.0-beta3 | |
Firefox | =4.0-beta4 | |
Firefox | =4.0-beta5 | |
Firefox | =4.0-beta6 | |
Firefox | =4.0-beta7 | |
Firefox | =4.0-beta8 | |
Firefox | =4.0-beta9 | |
Firefox | =4.0.1 | |
Firefox | =5.0 | |
Firefox | =5.0.1 | |
Firefox | =6.0 | |
Firefox | =6.0.1 | |
Firefox | =6.0.2 | |
Firefox | =7.0 | |
Firefox | =7.0.1 | |
Firefox | =8.0 | |
Firefox | =8.0.1 | |
Firefox | =9.0 | |
Firefox | =9.0.1 | |
Firefox | =10.0 | |
Firefox | =10.0.1 | |
Firefox | =10.0.2 | |
Firefox | =11.0 | |
Firefox | =12.0 | |
Firefox | =12.0-beta6 | |
Firefox | =13.0 | |
Thunderbird | <=14.0 | |
Thunderbird | =1.0 | |
Thunderbird | =1.0.1 | |
Thunderbird | =1.0.2 | |
Thunderbird | =1.0.3 | |
Thunderbird | =1.0.4 | |
Thunderbird | =1.0.5 | |
Thunderbird | =1.0.5-beta | |
Thunderbird | =1.0.6 | |
Thunderbird | =1.0.7 | |
Thunderbird | =1.0.8 | |
Thunderbird | =1.5 | |
Thunderbird | =1.5-beta2 | |
Thunderbird | =1.5.0.1 | |
Thunderbird | =1.5.0.2 | |
Thunderbird | =1.5.0.3 | |
Thunderbird | =1.5.0.4 | |
Thunderbird | =1.5.0.5 | |
Thunderbird | =1.5.0.6 | |
Thunderbird | =1.5.0.7 | |
Thunderbird | =1.5.0.8 | |
Thunderbird | =1.5.0.9 | |
Thunderbird | =1.5.0.10 | |
Thunderbird | =1.5.0.11 | |
Thunderbird | =1.5.0.12 | |
Thunderbird | =1.5.0.13 | |
Thunderbird | =1.5.0.14 | |
Thunderbird | =1.5.1 | |
Thunderbird | =1.5.2 | |
Thunderbird | =1.7.1 | |
Thunderbird | =1.7.3 | |
Thunderbird | =2.0 | |
Thunderbird | =2.0.0.0 | |
Thunderbird | =2.0.0.1 | |
Thunderbird | =2.0.0.2 | |
Thunderbird | =2.0.0.3 | |
Thunderbird | =2.0.0.4 | |
Thunderbird | =2.0.0.5 | |
Thunderbird | =2.0.0.6 | |
Thunderbird | =2.0.0.7 | |
Thunderbird | =2.0.0.8 | |
Thunderbird | =2.0.0.9 | |
Thunderbird | =2.0.0.11 | |
Thunderbird | =2.0.0.12 | |
Thunderbird | =2.0.0.13 | |
Thunderbird | =2.0.0.14 | |
Thunderbird | =2.0.0.15 | |
Thunderbird | =2.0.0.16 | |
Thunderbird | =2.0.0.17 | |
Thunderbird | =2.0.0.18 | |
Thunderbird | =2.0.0.19 | |
Thunderbird | =2.0.0.20 | |
Thunderbird | =2.0.0.21 | |
Thunderbird | =2.0.0.22 | |
Thunderbird | =2.0.0.23 | |
Thunderbird | =3.0 | |
Thunderbird | =3.0.1 | |
Thunderbird | =3.0.2 | |
Thunderbird | =3.0.3 | |
Thunderbird | =3.0.4 | |
Thunderbird | =3.0.5 | |
Thunderbird | =3.0.6 | |
Thunderbird | =3.0.7 | |
Thunderbird | =3.0.8 | |
Thunderbird | =3.0.9 | |
Thunderbird | =3.0.10 | |
Thunderbird | =3.0.11 | |
Thunderbird | =3.1 | |
Thunderbird | =3.1.1 | |
Thunderbird | =3.1.2 | |
Thunderbird | =3.1.3 | |
Thunderbird | =3.1.4 | |
Thunderbird | =3.1.5 | |
Thunderbird | =3.1.6 | |
Thunderbird | =3.1.7 | |
Thunderbird | =3.1.8 | |
Thunderbird | =3.1.9 | |
Thunderbird | =3.1.10 | |
Thunderbird | =3.1.11 | |
Thunderbird | =3.1.12 | |
Thunderbird | =3.1.13 | |
Thunderbird | =3.1.14 | |
Thunderbird | =3.1.15 | |
Thunderbird | =3.1.16 | |
Thunderbird | =3.1.17 | |
Thunderbird | =5.0 | |
Thunderbird | =6.0 | |
Thunderbird | =6.0.1 | |
Thunderbird | =6.0.2 | |
Thunderbird | =7.0 | |
Thunderbird | =7.0.1 | |
Thunderbird | =8.0 | |
Thunderbird | =9.0 | |
Thunderbird | =9.0.1 | |
Thunderbird | =10.0 | |
Thunderbird | =10.0.1 | |
Thunderbird | =10.0.2 | |
Thunderbird | =10.0.3 | |
Thunderbird | =10.0.4 | |
Thunderbird | =11.0 | |
Thunderbird | =12.0 | |
Thunderbird | =13.0 | |
Mozilla SeaMonkey | <=2.11 | |
Mozilla SeaMonkey | =2.0 | |
Mozilla SeaMonkey | =2.0-alpha_1 | |
Mozilla SeaMonkey | =2.0-alpha_2 | |
Mozilla SeaMonkey | =2.0-alpha_3 | |
Mozilla SeaMonkey | =2.0-beta_1 | |
Mozilla SeaMonkey | =2.0-beta_2 | |
Mozilla SeaMonkey | =2.0-rc1 | |
Mozilla SeaMonkey | =2.0-rc2 | |
Mozilla SeaMonkey | =2.0.1 | |
Mozilla SeaMonkey | =2.0.2 | |
Mozilla SeaMonkey | =2.0.3 | |
Mozilla SeaMonkey | =2.0.4 | |
Mozilla SeaMonkey | =2.0.5 | |
Mozilla SeaMonkey | =2.0.6 | |
Mozilla SeaMonkey | =2.0.7 | |
Mozilla SeaMonkey | =2.0.8 | |
Mozilla SeaMonkey | =2.0.9 | |
Mozilla SeaMonkey | =2.0.10 | |
Mozilla SeaMonkey | =2.0.11 | |
Mozilla SeaMonkey | =2.0.12 | |
Mozilla SeaMonkey | =2.0.13 | |
Mozilla SeaMonkey | =2.0.14 | |
Mozilla SeaMonkey | =2.1 | |
Mozilla SeaMonkey | =2.1-alpha1 | |
Mozilla SeaMonkey | =2.1-alpha2 | |
Mozilla SeaMonkey | =2.1-alpha3 | |
Mozilla SeaMonkey | =2.1-beta1 | |
Mozilla SeaMonkey | =2.1-beta2 | |
Mozilla SeaMonkey | =2.1-beta3 | |
Mozilla SeaMonkey | =2.1-rc1 | |
Mozilla SeaMonkey | =2.1-rc2 | |
Mozilla SeaMonkey | =2.2 | |
Mozilla SeaMonkey | =2.2-beta1 | |
Mozilla SeaMonkey | =2.2-beta2 | |
Mozilla SeaMonkey | =2.2-beta3 | |
Mozilla SeaMonkey | =2.3 | |
Mozilla SeaMonkey | =2.3-beta1 | |
Mozilla SeaMonkey | =2.3-beta2 | |
Mozilla SeaMonkey | =2.3-beta3 | |
Mozilla SeaMonkey | =2.3.1 | |
Mozilla SeaMonkey | =2.3.2 | |
Mozilla SeaMonkey | =2.3.3 | |
Mozilla SeaMonkey | =2.4 | |
Mozilla SeaMonkey | =2.4-beta1 | |
Mozilla SeaMonkey | =2.4-beta2 | |
Mozilla SeaMonkey | =2.4-beta3 | |
Mozilla SeaMonkey | =2.4.1 | |
Mozilla SeaMonkey | =2.5 | |
Mozilla SeaMonkey | =2.5-beta1 | |
Mozilla SeaMonkey | =2.5-beta2 | |
Mozilla SeaMonkey | =2.5-beta3 | |
Mozilla SeaMonkey | =2.5-beta4 | |
Mozilla SeaMonkey | =2.6 | |
Mozilla SeaMonkey | =2.6-beta1 | |
Mozilla SeaMonkey | =2.6-beta2 | |
Mozilla SeaMonkey | =2.6-beta3 | |
Mozilla SeaMonkey | =2.6-beta4 | |
Mozilla SeaMonkey | =2.6.1 | |
Mozilla SeaMonkey | =2.7 | |
Mozilla SeaMonkey | =2.7-beta1 | |
Mozilla SeaMonkey | =2.7-beta2 | |
Mozilla SeaMonkey | =2.7-beta3 | |
Mozilla SeaMonkey | =2.7-beta4 | |
Mozilla SeaMonkey | =2.7-beta5 | |
Mozilla SeaMonkey | =2.7.1 | |
Mozilla SeaMonkey | =2.7.2 | |
Mozilla SeaMonkey | =2.8 | |
Mozilla SeaMonkey | =2.8-beta1 | |
Mozilla SeaMonkey | =2.8-beta2 | |
Mozilla SeaMonkey | =2.8-beta3 | |
Mozilla SeaMonkey | =2.8-beta4 | |
Mozilla SeaMonkey | =2.8-beta5 | |
Mozilla SeaMonkey | =2.8-beta6 | |
Mozilla SeaMonkey | =2.9 | |
Mozilla SeaMonkey | =2.9-beta1 | |
Mozilla SeaMonkey | =2.9-beta2 | |
Mozilla SeaMonkey | =2.9-beta3 | |
Mozilla SeaMonkey | =2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3975 is classified as a medium severity vulnerability.
To fix CVE-2012-3975, upgrade to Mozilla Firefox, Thunderbird, or SeaMonkey version 15.0 or later.
Exploitation of CVE-2012-3975 can lead to unauthorized access to sensitive information by loading crafted subresources.
CVE-2012-3975 affects Mozilla Firefox versions prior to 15.0, Thunderbird versions prior to 15.0, and SeaMonkey versions prior to 2.12.
Users of outdated versions of Mozilla Firefox, Thunderbird, or SeaMonkey are at risk from CVE-2012-3975.