Mozilla Firefox before 9.0, Thunderbird before 9.0, and SeaMonkey before 2.6 on Mac OS X do not properly handle certain DOM frame deletions by plugins, which allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) or possibly have unspecified other impact via a crafted web site.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mfsa2011 57 | — | Upgrade to Mozilla Firefox version 9.0 | Jun 14, 2012 | Dec 20, 2011 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.6.0 | Feb 3, 2012 | Dec 20, 2011 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 9.0 | Feb 22, 2012 | Dec 20, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub