TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2012-0458

N/A

Beschreibung

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict setting the home page through the dragging of a URL to the home button, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a javascript: URL that is later interpreted in the about:sessionrestore context.

CVE Details

CVSS v3.1 BewertungN/A
Veroffentlicht3/14/2012
Zuletzt geandert4/29/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

mozilla:firefoxmozilla:seamonkeymozilla:thunderbirdmozilla:thunderbird_esr

Schwachen (CWE)

CWE-264

Referenzen

http://rhn.redhat.com/errata/RHSA-2012-0387.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2012-0388.html(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/48359(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/48402(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/48414(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/48495(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/48496(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/48513(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/48553(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/48561(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/48624(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/48629(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/48823(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/48920(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2012/dsa-2433(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2012/dsa-2458(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/52460(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id?1026801(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id?1026803(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id?1026804(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-1400-1(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-1400-2(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-1400-3(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-1400-4(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-1400-5(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-1401-1(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.mozilla.org/show_bug.cgi?id=718203(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.mozilla.org/show_bug.cgi?id=719994(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.mozilla.org/show_bug.cgi?id=723808(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.