CVE-2012-3990
- EPSS 6.07%
- Published 10.10.2012 17:55:01
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to exe...
CVE-2012-3991
- EPSS 1.42%
- Published 10.10.2012 17:55:01
- Last modified 11.04.2025 00:51:21
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which allows remote attackers to by...
CVE-2012-4929
- EPSS 13.87%
- Published 15.09.2012 18:55:03
- Last modified 11.04.2025 00:51:21
The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plain...
CVE-2012-4930
- EPSS 0.24%
- Published 15.09.2012 18:55:03
- Last modified 11.04.2025 00:51:21
The SPDY protocol 3 and earlier, as used in Mozilla Firefox, Google Chrome, and other products, can perform TLS encryption of compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to...
- EPSS 4.55%
- Published 29.08.2012 10:56:41
- Last modified 11.04.2025 00:51:21
The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to obtain sensit...
CVE-2012-3973
- EPSS 3.05%
- Published 29.08.2012 10:56:41
- Last modified 11.04.2025 00:51:21
The debugger in the developer-tools subsystem in Mozilla Firefox before 15.0, when remote debugging is disabled, does not properly restrict access to the remote-debugging service, which allows remote attackers to execute arbitrary code by leveraging ...
CVE-2012-3974
- EPSS 0.06%
- Published 29.08.2012 10:56:41
- Last modified 11.04.2025 00:51:21
Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 on Windows allows local users to gain privileges via a Trojan horse e...
CVE-2012-3975
- EPSS 0.92%
- Published 29.08.2012 10:56:41
- Last modified 11.04.2025 00:51:21
The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 loads subresources during parsing of text/html data within an extension, which allows remote attackers to obtain sensitive information by provi...
CVE-2012-3976
- EPSS 0.78%
- Published 29.08.2012 10:56:41
- Last modified 11.04.2025 00:51:21
Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoof the X.509 certificate inform...
CVE-2012-3978
- EPSS 1.75%
- Published 29.08.2012 10:56:41
- Last modified 11.04.2025 00:51:21
The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 does not properly follow the security model of the location objec...