CVE-2012-4193: Canonical Ubuntu Linux

Medium severity, CVSS 6.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 11.04 only; version 11.10 only; version 12.04 only
  • Mozilla Firefox: before 16.0.1 (fixed in 16.0.1); from 10.0, before 10.0.9 (fixed in 10.0.9)
  • Mozilla Seamonkey: before 2.13.1 (fixed in 2.13.1)
  • Mozilla Thunderbird: before 16.0.1 (fixed in 16.0.1)
  • Mozilla Thunderbird ESR: from 10.0, before 10.0.9 (fixed in 10.0.9)
  • Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only
  • Red Hat Enterprise Linux Eus: version 6.3 only
  • Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only
  • Suse Linux Enterprise Desktop: version 10 only; version 11 only
  • Suse Linux Enterprise Server: version 10 only; version 11 only
  • Suse Linux Enterprise Software Development Kit: version 10 only

Published 2012-10-12. Last modified 2026-06-16.