CVE-2012-0451

N/A Unknown
Published: March 14, 2012 Modified: April 29, 2026
View on NVD

Description

CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote web servers to bypass intended Content Security Policy (CSP) restrictions and possibly conduct cross-site scripting (XSS) attacks via crafted HTTP headers.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2012-03/msg00042.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://rhn.redhat.com/errata/RHSA-2012-0387.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://rhn.redhat.com/errata/RHSA-2012-0388.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/48359
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/48402
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/48496
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/48513
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/48553
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/48561
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/48629
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/49055
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDVSA-2012:032
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mozilla.org/security/announce/2012/mfsa2012-15.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/52463
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1026801
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1026803
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1026804
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/USN-1400-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/USN-1400-2
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/USN-1400-3
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/USN-1400-4
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/USN-1400-5
Source: af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.mozilla.org/show_bug.cgi?id=717511
Source: af854a3a-2127-422b-91ae-364da2661108

50 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
2.5%
82th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

mozilla