Loading...
Loading...
Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.
August 29, 2012
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2012-1956
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.