Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.802894
Category:General
Title:Mozilla Products Certificate Page Clickjacking Vulnerability - Mac OS X
Summary:Mozilla Firefox/Thunderbird/Seamonkey is prone to clickjacking vulnerability.
Description:Summary:
Mozilla Firefox/Thunderbird/Seamonkey is prone to clickjacking vulnerability.

Vulnerability Insight:
The certificate warning functionality in
browser/components/certerror/content/aboutCertError.xhtml fails to handle
attempted clickjacking of the 'about:certerror' page, allowing
man-in-the-middle attackers to trick users into adding an unintended
exception via an IFRAME element

Vulnerability Impact:
Successful exploitation could allow attackers to gain sensitive information
or bypass certain security restrictions.

Affected Software/OS:
SeaMonkey version before 2.10
Thunderbird version 5.0 through 12.0
Mozilla Firefox version 4.x through 12.0
Thunderbird ESR version 10.x before 10.0.6
Mozilla Firefox ESR version 10.x before 10.0.6 on Mac OS X

Solution:
Upgrade to Mozilla Firefox version 14.0 or ESR version 10.0.6 or later.

Upgrade to SeaMonkey version to 2.11 or later.

Upgrade to Thunderbird version to 14.0 or ESR 10.0.6 or later.

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:H/Au:N/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-1964
BugTraq ID: 54581
http://www.securityfocus.com/bid/54581
http://osvdb.org/84011
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16783
RedHat Security Advisories: RHSA-2012:1088
http://rhn.redhat.com/errata/RHSA-2012-1088.html
http://secunia.com/advisories/49965
http://secunia.com/advisories/49972
http://secunia.com/advisories/49977
http://secunia.com/advisories/49979
http://secunia.com/advisories/49992
http://secunia.com/advisories/49993
http://secunia.com/advisories/49994
SuSE Security Announcement: SUSE-SU-2012:0895 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00011.html
SuSE Security Announcement: SUSE-SU-2012:0896 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00012.html
SuSE Security Announcement: openSUSE-SU-2012:0899 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00013.html
http://www.ubuntu.com/usn/USN-1509-1
http://www.ubuntu.com/usn/USN-1509-2
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.