The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 does not properly follow the security model of the location object, which allows remote attackers to bypass intended content-loading restrictions or possibly have unspecified other impact via vectors involving chrome code.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2012-08-29T10:00:00

Updated: 2024-08-06T20:21:04.063Z

Reserved: 2012-07-11T00:00:00

Link: CVE-2012-3978

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2012-08-29T10:56:41.207

Modified: 2017-09-19T01:35:14.230

Link: CVE-2012-3978

cve-icon Redhat

Severity : Moderate

Publid Date: 2012-08-28T00:00:00Z

Links: CVE-2012-3978 - Bugzilla