CVE-2012-5354
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has multiple menus of SELECT elements active, which allows remote attackers to conduct clickjacking attacks via vectors involving an XPI file, the window.open method, and the Geolocation API, a different vulnerability than CVE-2012-3984.
Mozilla Firefox anteriores a v16.0, Thunderbird anteriores a v16.0 y SeaMonkey anteriores a v2.13 no manejan apropiadamente la navegación fuera de una página web que tenga múltiples menús de elementos SELECT activos, permitiendo a atacantes remotos realizar ataques de clickjacking mediante vectores relacionados con un fichero XPI, el método window.open y la API de geo-localización, siendo una vulnerabilidad diferente que CVE-2012-3984.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-10-10 CVE Reserved
- 2012-10-10 CVE Published
- 2023-04-28 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://osvdb.org/86171 | Broken Link | |
http://secunia.com/advisories/50856 | Broken Link | |
http://secunia.com/advisories/50935 | Broken Link | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16972 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.mozilla.org/security/announce/2012/mfsa2012-75.html | 2020-08-26 | |
https://bugzilla.mozilla.org/show_bug.cgi?id=726264 | 2020-08-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | < 16.0 Search vendor "Mozilla" for product "Firefox" and version " < 16.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Seamonkey Search vendor "Mozilla" for product "Seamonkey" | < 2.13 Search vendor "Mozilla" for product "Seamonkey" and version " < 2.13" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | < 16.0 Search vendor "Mozilla" for product "Thunderbird" and version " < 16.0" | - |
Affected
|