The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScript code by bookmarklets, which allows user-assisted remote attackers to run arbitrary programs by leveraging a javascript: URL in a bookmark.
CVSS Details
- CVSS 3.1 Base Score: 7.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-firefoxUpgrade linux-thunderbirdUpgrade linux-seamonkeyUpgrade libxulUpgrade thunderbirdUpgrade seamonkeyUpgrade firefox | Dec 10, 2025 | Nov 20, 2012 |
| Mfsa2012 95 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 17.0 | Nov 21, 2012 | Nov 20, 2012 |
| Suse | — | Upgrade mozilla-nss-x86Upgrade mozilla-nss-toolsUpgrade mozilla-nss-develUpgrade MozillaFirefox-translationsUpgrade libfreebl3-32bitUpgrade MozillaFirefox-translations-otherUpgrade mozilla-nss-32bitUpgrade MozillaFirefoxUpgrade libfreebl3Upgrade MozillaFirefox-develUpgrade mozilla-nssUpgrade libfreebl3-x86Upgrade MozillaFirefox-translations-common | Feb 17, 2015 | Jun 27, 2013 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Nov 21, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub