Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mark Poticha

#51236of 53,630
4.3Total CVSS
Vulnerabilities · 1
PT-2012-5104
4.3
2012-08-28
Mozilla · Firefox · CVE-2012-3976
**Name of the Vulnerable Software and Affected Versions** Mozilla Firefox versions prior to 15.0 Firefox ESR versions prior to 10.0.7 SeaMonkey versions prior to 2.12 **Description** The issue arises from improper handling of onLocationChange events during navigation between different https sites. This allows remote attackers to spoof the X.509 certificate information in the address bar via a crafted web page. **Recommendations** For Mozilla Firefox versions prior to 15.0, update to version 15.0 or later. For Firefox ESR versions prior to 10.0.7, update to version 10.0.7 or later. For SeaMonkey versions prior to 2.12, update to version 2.12 or later.