CVE-2012-3984

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has a SELECT element's menu active, which allows remote attackers to spoof page content via vectors involving absolute positioning and scrolling.

References

http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.html

http://secunia.com/advisories/50856

http://secunia.com/advisories/50892

http://secunia.com/advisories/50904

http://secunia.com/advisories/50935

http://secunia.com/advisories/50984

http://www.mozilla.org/security/announce/2012/mfsa2012-75.html

http://www.ubuntu.com/usn/USN-1611-1

https://bugzilla.mozilla.org/show_bug.cgi?id=575294

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16184

Details

Source: MITRE

Published: 2012-10-10

Updated: 2020-08-26

Risk Information

CVSS v2

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

Tenable Plugins

View all (19 total)

IDNameProductFamilySeverity
83562SUSE SLED10 / SLED11 / SLES10 / SLES11 Security Update : Mozilla Firefox (SUSE-SU-2012:1351-1)NessusSuSE Local Security Checks
critical
74779openSUSE Security Update : MozillaFirefox (openSUSE-SU-2012:1345-1)NessusSuSE Local Security Checks
critical
64133SuSE 11.2 Security Update : Mozilla Firefox (SAT Patch Number 6951)NessusSuSE Local Security Checks
critical
63402GLSA-201301-01 : Mozilla Products: Multiple vulnerabilities (BEAST)NessusGentoo Local Security Checks
critical
62583SeaMonkey < 2.13 Multiple VulnerabilitiesNessusWindows
critical
62582Mozilla Thunderbird < 16.0 Multiple VulnerabilitiesNessusWindows
critical
62580Firefox < 16.0 Multiple VulnerabilitiesNessusWindows
critical
62578Mozilla Thunderbird < 16.0 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
62576Firefox < 16.0 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
62573SuSE 10 Security Update : Mozilla Firefox (ZYPP Patch Number 8327)NessusSuSE Local Security Checks
critical
801325Mozilla Firefox 15.x <= 15 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801323Mozilla Thunderbird 15.x <= 15 Multiple VulnerabilitiesLog Correlation EngineSMTP Clients
high
801301Mozilla SeaMonkey 2.x < 2.13 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
6604Mozilla Thunderbird < 16.0.1 Multiple VulnerabilitiesNessus Network MonitorSMTP Clients
high
6603SeaMonkey 2.x < 2.13 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
6602Mozilla Firefox < 16.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
62548Ubuntu 10.04 LTS / 11.04 / 11.10 / 12.04 LTS : thunderbird vulnerabilities (USN-1611-1)NessusUbuntu Local Security Checks
critical
62490FreeBSD : mozilla -- multiple vulnerabilities (6e5a9afd-12d3-11e2-b47d-c8600054b392)NessusFreeBSD Local Security Checks
critical
62476Ubuntu 10.04 LTS / 11.04 / 11.10 / 12.04 LTS : firefox vulnerabilities (USN-1600-1)NessusUbuntu Local Security Checks
critical