CVE-2012-4210: Critical severity firefox vulnerability
The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not properly restrict the context of HTML markup and Cascading Style Sheets (CSS) token sequences, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted stylesheet.
Affected Software
Event History
Frequently Asked Questions
What are the risks associated with CVE-2012-4210?
CVE-2012-4210 allows remote attackers to execute arbitrary JavaScript code with elevated privileges in affected versions of Mozilla Firefox.
Which versions of Mozilla Firefox are affected by CVE-2012-4210?
CVE-2012-4210 affects Mozilla Firefox versions prior to 17.0 and Firefox ESR versions prior to 10.0.11.
How can I mitigate the risks of CVE-2012-4210?
To mitigate CVE-2012-4210, upgrade to Mozilla Firefox version 17.0 or later, or Firefox ESR version 10.0.11 or later.
Is there a workaround for CVE-2012-4210 if I cannot update immediately?
Disabling JavaScript in Firefox may temporarily mitigate the risks associated with CVE-2012-4210.
What is the impact of an exploit of CVE-2012-4210?
Exploiting CVE-2012-4210 can lead to arbitrary code execution, allowing an attacker to gain control over the affected system.