CVE-2012-1966
Publication date 17 July 2012
Last updated 24 July 2024
Ubuntu priority
Description
Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not have the same context-menu restrictions for data: URLs as for javascript: URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| firefox | ||
| seamonkey | ||
| thunderbird | ||
| xulrunner-1.9.2 | ||
| xulrunner-2.0 | ||
References
Related Ubuntu Security Notices (USN)
- USN-1509-1
- Firefox vulnerabilities
- 17 July 2012