Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Mark Poticha

#53866of 56,330
4.3Total CVSS
Vulnerabilities · 1
PT-2012-5104
4.3
2012-08-28
Mozilla · Firefox · CVE-2012-3976
**Name of the Vulnerable Software and Affected Versions** Mozilla Firefox versions prior to 15.0 Firefox ESR versions prior to 10.0.7 SeaMonkey versions prior to 2.12 **Description** The issue arises from improper handling of onLocationChange events during navigation between different https sites. This allows remote attackers to spoof the X.509 certificate information in the address bar via a crafted web page. **Recommendations** For Mozilla Firefox versions prior to 15.0, update to version 15.0 or later. For Firefox ESR versions prior to 10.0.7, update to version 10.0.7 or later. For SeaMonkey versions prior to 2.12, update to version 2.12 or later.