VYPR
Unrated severityNVD Advisory· Published Feb 1, 2012· Updated Apr 29, 2026

CVE-2012-0446

CVE-2012-0446

Description

Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to inject arbitrary web script or HTML via a (1) web page or (2) Firefox extension, related to improper enforcement of XPConnect security restrictions for frame scripts that call untrusted objects.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Mozilla Firefox, Thunderbird, and SeaMonkey are vulnerable to XSS via frame scripts bypassing XPConnect security checks.

Vulnerability

The vulnerability resides in Mozilla's XPConnect security enforcement for frame scripts. Frame scripts run in a special JavaScript context where SetSecurityManagerForJSContext is called with flags=0, causing XPConnect to skip proper security checks when a frame script calls an untrusted object [1]. This affects Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7. Firefox 3.6 and Thunderbird 3.1 are not affected [2].

Exploitation

An attacker can exploit this by crafting a malicious web page or Firefox extension that causes a frame script to invoke an untrusted object. The attacker must deliver the malicious content to the victim (e.g., via a web page or extension installation). No authentication is required, but user interaction may be needed to load the page or install the extension. When the frame script calls the untrusted object, the security check is bypassed, allowing arbitrary script execution in the context of the page or extension [1][2].

Impact

Successful exploitation allows remote attackers to inject arbitrary web script or HTML, resulting in cross-site scripting (XSS). This can lead to information disclosure, session hijacking, or other malicious actions within the victim's browser session. The impact is rated critical as it bypasses fundamental security restrictions [2].

Mitigation

The vulnerability is fixed in Firefox 10, SeaMonkey 2.7, and Thunderbird 10, released on January 31, 2012. Users should update to these versions or later. No workarounds are documented in the available references [2].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

132
  • cpe:2.3:a:mozilla:firefox:4.0:*:*:*:*:*:*:*+ 23 more
    • cpe:2.3:a:mozilla:firefox:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta10:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta11:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta12:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta6:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta7:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta8:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta9:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:5.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:6.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:6.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:8.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:9.0:*:*:*:*:*:*:*
    • (no CPE)range: 4.0 - 9.0
  • cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*+ 96 more
    • cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0:alpha:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.15:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.16:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.17:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.18:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.19:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1:alpha:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1:beta:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:beta_1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:beta_2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.1:alpha1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.1:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.1:alpha3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.1:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.1:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.1:beta3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.1:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.1:rc2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.2:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.2:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.2:beta3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.3:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.3:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.3:beta3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.4:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.4:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.4:beta3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.5:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.5:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.5:beta3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.5:beta4:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.6:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.6:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.6:beta3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.6:beta4:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.7:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.7:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.7:beta3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.7:beta4:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:*:beta5:*:*:*:*:*:*range: <=2.7
    • (no CPE)range: <2.7
  • cpe:2.3:a:mozilla:thunderbird:5.0:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:mozilla:thunderbird:5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:6.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:6.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:9.0:*:*:*:*:*:*:*
    • (no CPE)range: 5.0 - 9.0
  • osv-coords3 versions
    < 128.5.1-1.1+ 2 more
    • (no CPE)range: < 128.5.1-1.1
    • (no CPE)range: < 50.1.0-1.1
    • (no CPE)range: < 45.5.1-1.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.