Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote attackers to bypass an IPv6 literal ACL via a cross-site (1) XMLHttpRequest or (2) WebSocket operation involving a nonstandard port number and an IPv6 address that contains certain zero fields.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-firefoxUpgrade linux-thunderbirdUpgrade linux-seamonkeyUpgrade thunderbirdUpgrade firefoxUpgrade libxulUpgrade seamonkey | Dec 10, 2025 | Apr 24, 2012 |
| Gentoo Linux | — | Upgrade www-client/seamonkey.Upgrade mail-client/thunderbird-bin.Upgrade www-client/mozilla-firefox.Upgrade dev-libs/nss.Upgrade www-client/icecat.Upgrade net-libs/xulrunner.Upgrade www-client/firefox.Upgrade www-client/seamonkey-bin.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/thunderbird.Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/firefox-bin.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Apr 25, 2012 |
| Mfsa2012 28 | — | Upgrade to Mozilla Firefox version 12.0Upgrade to the latest version of Mozilla Firefox | Jun 14, 2012 | Apr 25, 2012 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.9.0 | Apr 27, 2012 | Apr 25, 2012 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 12.0 | Apr 27, 2012 | Apr 25, 2012 |
| Suse | — | Upgrade MozillaThunderbird-develUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translationsUpgrade MozillaThunderbird-translations-commonUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefoxUpgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbird | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade firefoxUpgrade thunderbird | Nov 8, 2024 | Apr 25, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub