Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has multiple menus of SELECT elements active, which allows remote attackers to conduct clickjacking attacks via vectors involving an XPI file, the window.open method, and the Geolocation API, a different vulnerability than CVE-2012-3984.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/seamonkey-bin.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/firefox-bin.Upgrade dev-libs/nss.Upgrade mail-client/thunderbird-bin.Upgrade www-client/mozilla-firefox.Upgrade net-libs/xulrunner.Upgrade www-client/firefox.Upgrade mail-client/thunderbird.Upgrade www-client/icecat.Upgrade www-client/seamonkey. | Oct 30, 2017 | Oct 10, 2012 |
| Mfsa2012 75 | — | Upgrade to Mozilla Firefox version 16.0 | May 7, 2018 | Oct 10, 2012 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.13.0 | May 7, 2018 | Oct 10, 2012 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 16.0 | May 7, 2018 | Oct 10, 2012 |
| Ubuntu | — | Upgrade firefoxUpgrade thunderbird | Nov 19, 2024 | Oct 10, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub