FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-0446

This CVE name corresponds to:

Entered Topic
2012-02-01 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-0446
Phase Assigned(20120109)

Description

Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to inject arbitrary web script or HTML via a (1) web page or (2) Firefox extension, related to improper enforcement of XPConnect security restrictions for frame scripts that call untrusted objects.

References

Source Reference
CONFIRM http://www.mozilla.org/security/announce/2012/mfsa2012-05.html
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=705651
MANDRIVA MDVSA-2012:013
SUSE openSUSE-SU-2012:0234
BID 51752
OVAL oval:org.mitre.oval:def:14304
SECUNIA 49055
XF mozilla-xpconnect-xss(72837)