CVE-2012-4193: Canonical Ubuntu Linux
Medium severity, CVSS 6.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.
Affected products
- Canonical Ubuntu Linux: version 10.04 only; version 11.04 only; version 11.10 only; version 12.04 only
- Mozilla Firefox: before 16.0.1 (fixed in 16.0.1); from 10.0, before 10.0.9 (fixed in 10.0.9)
- Mozilla Seamonkey: before 2.13.1 (fixed in 2.13.1)
- Mozilla Thunderbird: before 16.0.1 (fixed in 16.0.1)
- Mozilla Thunderbird ESR: from 10.0, before 10.0.9 (fixed in 10.0.9)
- Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Eus: version 6.3 only
- Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only
- Suse Linux Enterprise Desktop: version 10 only; version 11 only
- Suse Linux Enterprise Server: version 10 only; version 11 only
- Suse Linux Enterprise Software Development Kit: version 10 only
Published 2012-10-12. Last modified 2026-06-16.