CVE-2012-4207: XSS
The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handle a ~ (tilde) character in proximity to a chunk delimiter, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4207?
The severity of CVE-2012-4207 is classified as moderate.
How do I fix CVE-2012-4207?
To fix CVE-2012-4207, update to Mozilla Firefox versions 17.0 or later, Thunderbird 17.0 or later, and SeaMonkey 2.14 or later.
Which software is affected by CVE-2012-4207?
CVE-2012-4207 affects Mozilla Firefox versions prior to 17.0, Thunderbird prior to 17.0, and SeaMonkey prior to 2.14.
Is CVE-2012-4207 present in Firefox ESR 10.x?
Yes, CVE-2012-4207 affects Firefox ESR 10.x versions before 10.0.11.
Can CVE-2012-4207 be exploited remotely?
Yes, CVE-2012-4207 can be exploited remotely, allowing attackers to conduct various attacks.