Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2012-1950

The drag-and-drop implementation in Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 allows remote attackers to spoof the address bar by canceling a page load.

  • Published: Jul 18, 2012
  • Updated: Apr 13, 2023
  • CVE: CVE-2012-1950
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.4
  • AV:N/AC:L/Au:N/C:N/I:P/A:P

No CWE or OWASP classifications available.

Software From Fixed in
mozilla / firefox 4.0-beta6 4.0-beta6.x
mozilla / firefox 4.0-beta1 4.0-beta1.x
mozilla / firefox 8.0 8.0.x
mozilla / firefox 4.0-beta9 4.0-beta9.x
mozilla / firefox 4.0-beta5 4.0-beta5.x
mozilla / firefox 4.0-beta8 4.0-beta8.x
mozilla / firefox 4.0-beta12 4.0-beta12.x
mozilla / firefox 4.0-beta3 4.0-beta3.x
mozilla / firefox 5.0.1 5.0.1.x
mozilla / firefox 5.0 5.0.x
mozilla / firefox 7.0 7.0.x
mozilla / firefox 6.0.2 6.0.2.x
mozilla / firefox 4.0-beta2 4.0-beta2.x
mozilla / firefox 4.0-beta4 4.0-beta4.x
mozilla / firefox 13.0 13.0.x
mozilla / firefox 4.0-beta10 4.0-beta10.x
mozilla / firefox 12.0-beta6 12.0-beta6.x
mozilla / firefox 6.0.1 6.0.1.x
mozilla / firefox 4.0 4.0.x
mozilla / firefox 11.0 11.0.x
mozilla / firefox 6.0 6.0.x
mozilla / firefox 7.0.1 7.0.1.x
mozilla / firefox 4.0-beta11 4.0-beta11.x
mozilla / firefox 12.0 12.0.x
mozilla / firefox 8.0.1 8.0.1.x
mozilla / firefox 9.0.1 9.0.1.x
mozilla / firefox 4.0-beta7 4.0-beta7.x
mozilla / firefox 9.0 9.0.x
mozilla / firefox 4.0.1 4.0.1.x
mozilla / firefox_esr 10.0 10.0.x
mozilla / firefox_esr 10.0.5 10.0.5.x
mozilla / firefox_esr 10.0.2 10.0.2.x
mozilla / firefox_esr 10.0.1 10.0.1.x
mozilla / firefox_esr 10.0.3 10.0.3.x
mozilla / firefox_esr 10.0.4 10.0.4.x