Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to bypass the HTML5 frame-navigation policy and replace arbitrary sub-frames by creating a form submission target with a sub-frame's name attribute.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefoxUpgrade seamonkeyUpgrade linux-firefoxUpgrade linux-thunderbirdUpgrade linux-seamonkeyUpgrade thunderbird | Dec 10, 2025 | Feb 1, 2012 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey.Upgrade www-client/firefox-bin.Upgrade net-libs/xulrunner-bin.Upgrade www-client/firefox.Upgrade www-client/seamonkey-bin.Upgrade dev-libs/nss.Upgrade mail-client/thunderbird-bin.Upgrade net-libs/xulrunner.Upgrade www-client/icecat.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/mozilla-thunderbird. | Oct 30, 2017 | Feb 1, 2012 |
| Mfsa2012 03 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 10.0 | Jun 14, 2012 | Feb 1, 2012 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.7.0 | Feb 3, 2012 | Feb 1, 2012 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 10.0 | Feb 22, 2012 | Feb 1, 2012 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.1.0.0.24.2 on Solaris 11.1 | May 29, 2017 | Feb 1, 2012 |
| Suse | — | Upgrade MozillaThunderbird-develUpgrade MozillaFirefox-translationsUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-otherUpgrade MozillaThunderbird-translations-commonUpgrade MozillaThunderbirdUpgrade MozillaFirefox-translations-commonUpgrade MozillaThunderbird-translations-otherUpgrade MozillaFirefox-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade firefoxUpgrade thunderbird | Nov 8, 2024 | Feb 1, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub