Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16367 | vdb entry signature |
http://rhn.redhat.com/errata/RHSA-2012-1351.html | vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=756719 | |
http://www.securityfocus.com/bid/55260 | vdb entry |
http://www.mozilla.org/security/announce/2012/mfsa2012-59.html | vendor advisory |
http://www.ubuntu.com/usn/USN-1548-1 | vendor advisory |
http://www.ubuntu.com/usn/USN-1548-2 | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00028.html | vendor advisory |