Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:Red Hat Local Security Checks
Title:RedHat Update for firefox RHSA-2012:1088-01
Summary:The remote host is missing an update for the 'firefox'; package(s) announced via the referenced advisory.
The remote host is missing an update for the 'firefox'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A web page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2012-1948, CVE-2012-1951, CVE-2012-1952, CVE-2012-1953,
CVE-2012-1954, CVE-2012-1958, CVE-2012-1962, CVE-2012-1967)

A malicious web page could bypass same-compartment security wrappers (SCSW)
and execute arbitrary code with chrome privileges. (CVE-2012-1959)

A flaw in the context menu functionality in Firefox could allow a malicious
website to bypass intended restrictions and allow a cross-site scripting
attack. (CVE-2012-1966)

A page different to that in the address bar could be displayed when
dragging and dropping to the address bar, possibly making it easier for a
malicious site or user to perform a phishing attack. (CVE-2012-1950)

A flaw in the way Firefox called history.forward and history.back could
allow an attacker to conceal a malicious URL, possibly tricking a user
into believing they are viewing a trusted site. (CVE-2012-1955)

A flaw in a parser utility class used by Firefox to parse feeds (such as
RSS) could allow an attacker to execute arbitrary JavaScript with the
privileges of the user running Firefox. This issue could have affected
other browser components or add-ons that assume the class returns
sanitized input. (CVE-2012-1957)

A flaw in the way Firefox handled X-Frame-Options headers could allow a
malicious website to perform a clickjacking attack. (CVE-2012-1961)

A flaw in the way Content Security Policy (CSP) reports were generated by
Firefox could allow a malicious web page to steal a victim's OAuth 2.0
access tokens and OpenID credentials. (CVE-2012-1963)

A flaw in the way Firefox handled certificate warnings could allow a
man-in-the-middle attacker to create a crafted warning, possibly tricking
a user into accepting an arbitrary certificate as trusted. (CVE-2012-1964)

A flaw in the way Firefox handled feed:javascript URLs could allow output
filtering to be bypassed, possibly leading to a cross-site scripting
attack. (CVE-2012-1965)

The nss update RHBA-2012:0337 for Red Hat Enterprise Linux 5 and 6
introduced a mitigation for the CVE-2011-3389 flaw. For compatibility
reasons, it remains disabled by default in the nss packages. This update

Description truncated, please see the referenced URL(s) for more information.

Affected Software/OS:
firefox on Red Hat Enterprise Linux (v. 5 server),
Red Hat Enterprise Linux Desktop (v. 6),
Red Hat Enterprise Linux Server (v. 6),
Red Hat Enterprise Linux Workstation (v. 6)

Please Install the Updated Packages.

CVSS Score:

CVSS Vector:

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-1948
BugTraq ID: 54580
Debian Security Information: DSA-2514 (Google Search)
Debian Security Information: DSA-2528 (Google Search)
RedHat Security Advisories: RHSA-2012:1088
SuSE Security Announcement: SUSE-SU-2012:0895 (Google Search)
SuSE Security Announcement: SUSE-SU-2012:0896 (Google Search)
SuSE Security Announcement: openSUSE-SU-2012:0899 (Google Search)
SuSE Security Announcement: openSUSE-SU-2012:0917 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2012-1950
Common Vulnerability Exposure (CVE) ID: CVE-2012-1951
BugTraq ID: 54578
Common Vulnerability Exposure (CVE) ID: CVE-2012-1952
Common Vulnerability Exposure (CVE) ID: CVE-2012-1953
Common Vulnerability Exposure (CVE) ID: CVE-2012-1954
Common Vulnerability Exposure (CVE) ID: CVE-2012-1955
BugTraq ID: 54586
Common Vulnerability Exposure (CVE) ID: CVE-2012-1957
BugTraq ID: 54583
Common Vulnerability Exposure (CVE) ID: CVE-2012-1958
BugTraq ID: 54574
Common Vulnerability Exposure (CVE) ID: CVE-2012-1959
BugTraq ID: 54576
Common Vulnerability Exposure (CVE) ID: CVE-2012-1961
BugTraq ID: 54584
Common Vulnerability Exposure (CVE) ID: CVE-2012-1962
BugTraq ID: 54575
Common Vulnerability Exposure (CVE) ID: CVE-2012-1963
BugTraq ID: 54582
Common Vulnerability Exposure (CVE) ID: CVE-2012-1964
BugTraq ID: 54581
Common Vulnerability Exposure (CVE) ID: CVE-2012-1965
BugTraq ID: 54579
Common Vulnerability Exposure (CVE) ID: CVE-2012-1966
BugTraq ID: 54577
Common Vulnerability Exposure (CVE) ID: CVE-2012-1967
BugTraq ID: 54573
Common Vulnerability Exposure (CVE) ID: CVE-2011-3389
BugTraq ID: 49388
BugTraq ID: 49778
Cert/CC Advisory: TA12-010A
CERT/CC vulnerability note: VU#864643
Debian Security Information: DSA-2398 (Google Search)
HPdes Security Advisory: HPSBMU02742
HPdes Security Advisory: HPSBMU02797
HPdes Security Advisory: HPSBMU02799
HPdes Security Advisory: HPSBMU02900
HPdes Security Advisory: HPSBUX02730
HPdes Security Advisory: HPSBUX02760
HPdes Security Advisory: HPSBUX02777
HPdes Security Advisory: SSRT100710
HPdes Security Advisory: SSRT100740
HPdes Security Advisory: SSRT100805
HPdes Security Advisory: SSRT100854
HPdes Security Advisory: SSRT100867
Microsoft Security Bulletin: MS12-006
RedHat Security Advisories: RHSA-2012:0508
RedHat Security Advisories: RHSA-2013:1455
SuSE Security Announcement: SUSE-SU-2012:0114 (Google Search)
SuSE Security Announcement: SUSE-SU-2012:0122 (Google Search)
SuSE Security Announcement: SUSE-SU-2012:0602 (Google Search)
SuSE Security Announcement: openSUSE-SU-2012:0030 (Google Search)
SuSE Security Announcement: openSUSE-SU-2012:0063 (Google Search)
SuSE Security Announcement: openSUSE-SU-2020:0086 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2012-1949
CopyrightCopyright (c) 2012 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2021 E-Soft Inc. All rights reserved.