CVE-2012-1956
Published: 29 August 2012
Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.
Priority
Status
Package | Release | Status |
---|---|---|
firefox Launchpad, Ubuntu, Debian |
hardy |
Ignored
(reached end-of-life)
|
lucid |
Released
(15.0+build1-0ubuntu0.10.04.1)
|
|
natty |
Released
(15.0+build1-0ubuntu0.11.04.2)
|
|
oneiric |
Released
(15.0+build1-0ubuntu0.11.10.1)
|
|
precise |
Released
(15.0+build1-0ubuntu0.12.04.1)
|
|
quantal |
Released
(15.0+build1-0ubuntu1)
|
|
raring |
Released
(15.0+build1-0ubuntu1)
|
|
saucy |
Released
(15.0+build1-0ubuntu1)
|
|
upstream |
Released
(15.0)
|
|
seamonkey Launchpad, Ubuntu, Debian |
hardy |
Ignored
(reached end-of-life)
|
lucid |
Ignored
(reached end-of-life)
|
|
natty |
Ignored
(reached end-of-life)
|
|
oneiric |
Ignored
(reached end-of-life)
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
saucy |
Does not exist
|
|
upstream |
Needs triage
|
|
thunderbird Launchpad, Ubuntu, Debian |
hardy |
Ignored
(reached end-of-life)
|
lucid |
Released
(15.0+build1-0ubuntu0.10.04.1)
|
|
natty |
Released
(15.0+build1-0ubuntu0.11.04.1)
|
|
oneiric |
Released
(15.0+build1-0ubuntu0.11.10.1)
|
|
precise |
Released
(15.0+build1-0ubuntu0.12.04.1)
|
|
quantal |
Released
(15.0+build1-0ubuntu1)
|
|
raring |
Released
(15.0+build1-0ubuntu1)
|
|
saucy |
Released
(15.0+build1-0ubuntu1)
|
|
upstream |
Released
(15.0)
|
|
xulrunner-1.9.2 Launchpad, Ubuntu, Debian |
hardy |
Ignored
(reached end-of-life)
|
lucid |
Ignored
(see notes)
|
|
natty |
Ignored
(universe-binary)
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
saucy |
Does not exist
|
|
upstream |
Needs triage
|
|
xulrunner-2.0 Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Does not exist
|
|
natty |
Ignored
(does not process internet content)
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
saucy |
Does not exist
|
|
upstream |
Needs triage
|