2.6
CVSSv2

CVE-2012-0475

Published: 25/04/2012 Updated: 19/12/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Mozilla Firefox 4.x up to and including 11.0, Thunderbird 5.0 up to and including 11.0, and SeaMonkey prior to 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote malicious users to bypass an IPv6 literal ACL via a cross-site (1) XMLHttpRequest or (2) WebSocket operation involving a nonstandard port number and an IPv6 address that contains certain zero fields.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 4.0.1

mozilla firefox 4.0

mozilla firefox 5.0.1

mozilla firefox 6.0

mozilla firefox 9.0

mozilla firefox 10.0

mozilla firefox 6.0.2

mozilla firefox 6.0.1

mozilla firefox 7.0.1

mozilla firefox 10.0.1

mozilla firefox 10.0.2

mozilla firefox 7.0

mozilla firefox 8.0

mozilla firefox 11.0

mozilla firefox 5.0

mozilla firefox 8.0.1

mozilla firefox 9.0.1

mozilla thunderbird 6.0.1

mozilla thunderbird 6.0.2

mozilla thunderbird 10.0.2

mozilla thunderbird 10.0.3

mozilla thunderbird 10.0.4

mozilla thunderbird 7.0.1

mozilla thunderbird 7.0

mozilla thunderbird 11.0

mozilla thunderbird 9.0.1

mozilla thunderbird 8.0

mozilla thunderbird 9.0

mozilla thunderbird 5.0

mozilla thunderbird 6.0

mozilla thunderbird 10.0

mozilla thunderbird 10.0.1

mozilla seamonkey 2.8

mozilla seamonkey 2.9

mozilla seamonkey

mozilla seamonkey 2.0.2

mozilla seamonkey 1.1.15

mozilla seamonkey 2.0.13

mozilla seamonkey 2.0.14

mozilla seamonkey 2.0

mozilla seamonkey 2.0.4

mozilla seamonkey 1.1.19

mozilla seamonkey 1.1.18

mozilla seamonkey 2.0.9

mozilla seamonkey 2.1

mozilla seamonkey 2.5

mozilla seamonkey 2.4

mozilla seamonkey 2.3.2

mozilla seamonkey 2.6

mozilla seamonkey 2.6.1

mozilla seamonkey 1.0.8

mozilla seamonkey 1.1.3

mozilla seamonkey 2.3

mozilla seamonkey 2.2

mozilla seamonkey 1.1

mozilla seamonkey 2.7

mozilla seamonkey 1.1.17

mozilla seamonkey 2.0.11

mozilla seamonkey 2.0.1

mozilla seamonkey 1.0

mozilla seamonkey 1.1.10

mozilla seamonkey 1.1.8

mozilla seamonkey 2.0.8

mozilla seamonkey 2.3.3

mozilla seamonkey 1.1.6

mozilla seamonkey 2.7.1

mozilla seamonkey 2.7.2

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.11

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.4

mozilla seamonkey 2.0.7

mozilla seamonkey 1.1.7

mozilla seamonkey 1.1.9

mozilla seamonkey 2.3.1

mozilla seamonkey 1.5.0.8

mozilla seamonkey 1.0.6

mozilla seamonkey 1.1.13

mozilla seamonkey 1.0.4

mozilla seamonkey 1.0.7

mozilla seamonkey 1.1.2

mozilla seamonkey 1.0.5

mozilla seamonkey 2.0.6

mozilla seamonkey 2.0.5

mozilla seamonkey 1.1.14

mozilla seamonkey 2.0.12

mozilla seamonkey 1.1.5

mozilla seamonkey 2.0.3

mozilla seamonkey 2.4.1

mozilla seamonkey 2.0.10

mozilla seamonkey 1.5.0.9

mozilla seamonkey 1.0.9

mozilla seamonkey 1.5.0.10

mozilla seamonkey 1.0.1

mozilla seamonkey 1.0.3

mozilla seamonkey 1.0.2

Vendor Advisories

Debian Bug report logs - #703071 CVE-2011-1187, CVE-2012-0475, CVE-2013-{0773,0775,0776,0780,0782,0783} Package: iceweasel; Maintainer for iceweasel is Maintainers of Mozilla-related packages <team+pkg-mozilla@trackerdebianorg>; Source for iceweasel is src:firefox-esr (PTS, buildd, popcon) Reported by: Arne Wichmann <aw ...
Several security issues were fixed in Firefox ...
This update provides compatible ubufox packages for the latest Firefox ...
Several security issues were fixed in Thunderbird ...
Mozilla Foundation Security Advisory 2012-28 Ambiguous IPv6 in Origin headers may bypass webserver access restrictions Announced April 24, 2012 Reporter Simone Fabiano Impact Moderate Products Firefox, SeaMonkey, Thunderbird ...