CVE-2012-5354

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has multiple menus of SELECT elements active, which allows remote attackers to conduct clickjacking attacks via vectors involving an XPI file, the window.open method, and the Geolocation API, a different vulnerability than CVE-2012-3984.

References

http://osvdb.org/86171

http://secunia.com/advisories/50856

http://secunia.com/advisories/50935

http://www.mozilla.org/security/announce/2012/mfsa2012-75.html

https://bugzilla.mozilla.org/show_bug.cgi?id=726264

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16972

Details

Source: MITRE

Published: 2012-10-10

Updated: 2020-08-26

Risk Information

CVSS v2

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

Tenable Plugins

View all (12 total)

IDNameProductFamilySeverity
63402GLSA-201301-01 : Mozilla Products: Multiple vulnerabilities (BEAST)NessusGentoo Local Security Checks
critical
62583SeaMonkey < 2.13 Multiple VulnerabilitiesNessusWindows
critical
62582Mozilla Thunderbird < 16.0 Multiple VulnerabilitiesNessusWindows
critical
62580Firefox < 16.0 Multiple VulnerabilitiesNessusWindows
critical
62578Mozilla Thunderbird < 16.0 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
62576Firefox < 16.0 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
801325Mozilla Firefox 15.x <= 15 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801323Mozilla Thunderbird 15.x <= 15 Multiple VulnerabilitiesLog Correlation EngineSMTP Clients
high
801301Mozilla SeaMonkey 2.x < 2.13 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
6604Mozilla Thunderbird < 16.0.1 Multiple VulnerabilitiesNessus Network MonitorSMTP Clients
high
6603SeaMonkey 2.x < 2.13 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
6602Mozilla Firefox < 16.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high