[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-5354Date: (C)2012-10-10   (M)2024-03-27


Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has multiple menus of SELECT elements active, which allows remote attackers to conduct clickjacking attacks via vectors involving an XPI file, the window.open method, and the Geolocation API, a different vulnerability than CVE-2012-3984.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECUNIA-50856
SECUNIA-50935
OSVDB-86171
IAVM:2013-A-0009
http://www.mozilla.org/security/announce/2012/mfsa2012-75.html
https://bugzilla.mozilla.org/show_bug.cgi?id=726264
oval:org.mitre.oval:def:16972

CPE    363
cpe:/a:mozilla:firefox:14.0
cpe:/a:mozilla:firefox:1.5:beta2
cpe:/a:mozilla:thunderbird:11.0
cpe:/a:mozilla:firefox:1.5:beta1
...
OVAL    4
oval:org.secpod.oval:def:7632
oval:org.secpod.oval:def:7633
oval:org.secpod.oval:def:7590
oval:org.secpod.oval:def:7591
...

© SecPod Technologies