First published: Wed Nov 21 2012(Updated: )
The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not properly restrict the context of HTML markup and Cascading Style Sheets (CSS) token sequences, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted stylesheet.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <=16.0.2 | |
Firefox | =0.1 | |
Firefox | =0.2 | |
Firefox | =0.3 | |
Firefox | =0.4 | |
Firefox | =0.5 | |
Firefox | =0.6 | |
Firefox | =0.6.1 | |
Firefox | =0.7 | |
Firefox | =0.7.1 | |
Firefox | =0.8 | |
Firefox | =0.9 | |
Firefox | =0.9-rc | |
Firefox | =0.9.1 | |
Firefox | =0.9.2 | |
Firefox | =0.9.3 | |
Firefox | =0.10 | |
Firefox | =0.10.1 | |
Firefox | =1.0 | |
Firefox | =1.0-preview_release | |
Firefox | =1.0.1 | |
Firefox | =1.0.2 | |
Firefox | =1.0.3 | |
Firefox | =1.0.4 | |
Firefox | =1.0.5 | |
Firefox | =1.0.6 | |
Firefox | =1.0.7 | |
Firefox | =1.0.8 | |
Firefox | =1.4.1 | |
Firefox | =1.5 | |
Firefox | =1.5-beta1 | |
Firefox | =1.5-beta2 | |
Firefox | =1.5.0.1 | |
Firefox | =1.5.0.2 | |
Firefox | =1.5.0.3 | |
Firefox | =1.5.0.4 | |
Firefox | =1.5.0.5 | |
Firefox | =1.5.0.6 | |
Firefox | =1.5.0.7 | |
Firefox | =1.5.0.8 | |
Firefox | =1.5.0.9 | |
Firefox | =1.5.0.10 | |
Firefox | =1.5.0.11 | |
Firefox | =1.5.0.12 | |
Firefox | =1.5.1 | |
Firefox | =1.5.2 | |
Firefox | =1.5.3 | |
Firefox | =1.5.4 | |
Firefox | =1.5.5 | |
Firefox | =1.5.6 | |
Firefox | =1.5.7 | |
Firefox | =1.5.8 | |
Firefox | =1.8 | |
Firefox | =2.0 | |
Firefox | =2.0.0.1 | |
Firefox | =2.0.0.2 | |
Firefox | =2.0.0.3 | |
Firefox | =2.0.0.4 | |
Firefox | =2.0.0.5 | |
Firefox | =2.0.0.6 | |
Firefox | =2.0.0.7 | |
Firefox | =2.0.0.8 | |
Firefox | =2.0.0.9 | |
Firefox | =2.0.0.10 | |
Firefox | =2.0.0.11 | |
Firefox | =2.0.0.12 | |
Firefox | =2.0.0.13 | |
Firefox | =2.0.0.14 | |
Firefox | =2.0.0.15 | |
Firefox | =2.0.0.16 | |
Firefox | =2.0.0.17 | |
Firefox | =2.0.0.18 | |
Firefox | =2.0.0.19 | |
Firefox | =2.0.0.20 | |
Firefox | =3.0 | |
Firefox | =3.0.1 | |
Firefox | =3.0.2 | |
Firefox | =3.0.3 | |
Firefox | =3.0.4 | |
Firefox | =3.0.5 | |
Firefox | =3.0.6 | |
Firefox | =3.0.7 | |
Firefox | =3.0.8 | |
Firefox | =3.0.9 | |
Firefox | =3.0.10 | |
Firefox | =3.0.11 | |
Firefox | =3.0.12 | |
Firefox | =3.0.13 | |
Firefox | =3.0.14 | |
Firefox | =3.0.15 | |
Firefox | =3.0.16 | |
Firefox | =3.0.17 | |
Firefox | =3.5 | |
Firefox | =3.5.1 | |
Firefox | =3.5.2 | |
Firefox | =3.5.3 | |
Firefox | =3.5.4 | |
Firefox | =3.5.5 | |
Firefox | =3.5.6 | |
Firefox | =3.5.7 | |
Firefox | =3.5.8 | |
Firefox | =3.5.9 | |
Firefox | =3.5.10 | |
Firefox | =3.5.11 | |
Firefox | =3.5.12 | |
Firefox | =3.5.13 | |
Firefox | =3.5.14 | |
Firefox | =3.5.15 | |
Firefox | =3.6 | |
Firefox | =3.6.2 | |
Firefox | =3.6.3 | |
Firefox | =3.6.4 | |
Firefox | =3.6.6 | |
Firefox | =3.6.7 | |
Firefox | =3.6.8 | |
Firefox | =3.6.9 | |
Firefox | =3.6.10 | |
Firefox | =3.6.11 | |
Firefox | =3.6.12 | |
Firefox | =3.6.13 | |
Firefox | =3.6.14 | |
Firefox | =3.6.15 | |
Firefox | =3.6.16 | |
Firefox | =3.6.17 | |
Firefox | =3.6.18 | |
Firefox | =3.6.19 | |
Firefox | =3.6.20 | |
Firefox | =3.6.21 | |
Firefox | =3.6.22 | |
Firefox | =3.6.23 | |
Firefox | =3.6.24 | |
Firefox | =3.6.25 | |
Firefox | =4.0 | |
Firefox | =4.0-beta1 | |
Firefox | =4.0-beta10 | |
Firefox | =4.0-beta11 | |
Firefox | =4.0-beta12 | |
Firefox | =4.0-beta2 | |
Firefox | =4.0-beta3 | |
Firefox | =4.0-beta4 | |
Firefox | =4.0-beta5 | |
Firefox | =4.0-beta6 | |
Firefox | =4.0-beta7 | |
Firefox | =4.0-beta8 | |
Firefox | =4.0-beta9 | |
Firefox | =4.0.1 | |
Firefox | =5.0 | |
Firefox | =5.0.1 | |
Firefox | =6.0 | |
Firefox | =6.0.1 | |
Firefox | =6.0.2 | |
Firefox | =7.0 | |
Firefox | =7.0.1 | |
Firefox | =8.0 | |
Firefox | =8.0.1 | |
Firefox | =9.0 | |
Firefox | =9.0.1 | |
Firefox | =10.0 | |
Firefox | =10.0.1 | |
Firefox | =10.0.2 | |
Firefox | =11.0 | |
Firefox | =12.0 | |
Firefox | =12.0-beta6 | |
Firefox | =13.0 | |
Firefox | =13.0.1 | |
Firefox | =14.0 | |
Firefox | =14.0.1 | |
Firefox | =15.0 | |
Firefox | =15.0.1 | |
Firefox | =16.0 | |
Firefox | =16.0.1 | |
Firefox | =10.0.3 | |
Firefox | =10.0.4 | |
Firefox | =10.0.5 | |
Firefox | =10.0.6 | |
Firefox | =10.0.7 | |
Firefox | =10.0.8 | |
Firefox | =10.0.9 | |
Firefox | =10.0.10 | |
Firefox ESR | =10.0 | |
Firefox ESR | =10.0.1 | |
Firefox ESR | =10.0.2 | |
Firefox ESR | =10.0.3 | |
Firefox ESR | =10.0.4 | |
Firefox ESR | =10.0.5 | |
Firefox ESR | =10.0.6 | |
Firefox ESR | =10.0.7 | |
Firefox ESR | =10.0.8 | |
Firefox ESR | =10.0.9 | |
Firefox ESR | =10.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4210 allows remote attackers to execute arbitrary JavaScript code with elevated privileges in affected versions of Mozilla Firefox.
CVE-2012-4210 affects Mozilla Firefox versions prior to 17.0 and Firefox ESR versions prior to 10.0.11.
To mitigate CVE-2012-4210, upgrade to Mozilla Firefox version 17.0 or later, or Firefox ESR version 10.0.11 or later.
Disabling JavaScript in Firefox may temporarily mitigate the risks associated with CVE-2012-4210.
Exploiting CVE-2012-4210 can lead to arbitrary code execution, allowing an attacker to gain control over the affected system.