The Web Developer Toolbar in Mozilla Firefox before 17.0 executes script with chrome privileges, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-thunderbirdUpgrade linux-seamonkeyUpgrade libxulUpgrade firefoxUpgrade linux-firefoxUpgrade seamonkeyUpgrade thunderbird | Dec 10, 2025 | Nov 20, 2012 |
| Mfsa2012 102 | — | Upgrade to Mozilla Firefox version 17.0Upgrade to the latest version of Mozilla Firefox | Nov 14, 2013 | Nov 21, 2012 |
| Suse | — | Upgrade mozilla-nss-toolsUpgrade mozilla-nss-develUpgrade MozillaThunderbird-translations-otherUpgrade mozilla-nss-x86Upgrade MozillaThunderbirdUpgrade mozilla-nssUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translations-otherUpgrade libfreebl3Upgrade MozillaFirefox-develUpgrade MozillaThunderbird-develUpgrade MozillaFirefoxUpgrade MozillaThunderbird-translations-commonUpgrade libfreebl3-x86Upgrade MozillaFirefox-translationsUpgrade libfreebl3-32bitUpgrade mozilla-nss-32bit | Feb 17, 2015 | Jun 27, 2013 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Nov 21, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub