CVE-2012-4196: Medium severity firefox vulnerability
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4196?
CVE-2012-4196 has a CVSS score indicating it has a medium severity level due to its ability to bypass the Same Origin Policy.
How do I fix CVE-2012-4196?
To fix CVE-2012-4196, update Mozilla Firefox, Thunderbird, SeaMonkey, or their ESR versions to the latest releases that include security patches.
Which versions are affected by CVE-2012-4196?
CVE-2012-4196 affects Mozilla Firefox versions before 16.0.2, Thunderbird before 16.0.2, and certain versions of Firefox ESR and Thunderbird ESR.
Can CVE-2012-4196 be exploited remotely?
Yes, CVE-2012-4196 can be exploited remotely by attackers to read the Location object through a prototype property-injection attack.
What applications are impacted by CVE-2012-4196?
CVE-2012-4196 impacts Mozilla Firefox, Thunderbird, SeaMonkey, and the ESR versions of Firefox and Thunderbird.