The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not block inline event handlers, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade xulrunnerUpgrade xulrunner-develUpgrade firefoxUpgrade thunderbird | Dec 1, 2016 | Jun 5, 2012 |
| Freebsd | — | Upgrade seamonkeyUpgrade thunderbirdUpgrade linux-seamonkeyUpgrade firefoxUpgrade libxulUpgrade linux-thunderbirdUpgrade linux-firefox | Dec 10, 2025 | Jun 5, 2012 |
| Mfsa2012 36 | — | Upgrade to Mozilla Firefox ESR version 10.0.5Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 13.0 | Jun 14, 2012 | Jun 5, 2012 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.10.0 | Jun 19, 2012 | Jun 5, 2012 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird ESR version 10.0.5Upgrade to Mozilla Thunderbird version 13.0Upgrade to the latest version of Mozilla Thunderbird | Jun 19, 2012 | Jun 5, 2012 |
| Oracle_linux | — | Upgrade xulrunner-develUpgrade thunderbirdUpgrade firefoxUpgrade xulrunner | Oct 16, 2024 | Jun 5, 2012 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-commonUpgrade MozillaThunderbirdUpgrade MozillaFirefox-translationsUpgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbird-develUpgrade MozillaThunderbird-translations-commonUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-other | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade firefoxUpgrade thunderbird | Nov 8, 2024 | Jun 5, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub