CVE-2012-3985: Canonical Ubuntu Linux

Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 11.04 only; version 11.10 only; version 12.04 only
  • Mozilla Firefox: before 16.0 (fixed in 16.0)
  • Mozilla Seamonkey: before 2.13 (fixed in 2.13)
  • Mozilla Thunderbird: before 16.0 (fixed in 16.0)
  • Suse Linux Enterprise Desktop: version 10 only; version 11 only
  • Suse Linux Enterprise Server: version 10 only; version 11 only

Published 2012-10-10. Last modified 2026-06-16.