Loading...
Loading...
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.
October 10, 2012
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2012-3985
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.