CyberRota
Live Feed
Return to register
Case File

CVE-2012-0458

MEDIUM · CVSS 6.8 EPSS 2.77%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2012-03-14 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2012-0458
Severity
MEDIUM
CVSS
6.8
EPSS
2.77%
Chrome Firefox Java

Original Filing — NVD Description

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict setting the home page through the dragging of a URL to the home button, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a javascript: URL that is later interpreted in the about:sessionrestore context.