CVE-2012-3986
- EPSS 0.84%
- Veröffentlicht 10.10.2012 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils) methods, which allows remote a...
CVE-2012-3988
- EPSS 3.99%
- Veröffentlicht 10.10.2012 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 might allow user-assisted remote attackers to execute arbitrary code v...
CVE-2012-3989
- EPSS 0.85%
- Veröffentlicht 10.10.2012 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly perform a cast of an unspecified variable during use of the instanceof operator on a JavaScript object, which allows remote attackers to execute arbitrary...
CVE-2012-3990
- EPSS 6.07%
- Veröffentlicht 10.10.2012 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to exe...
CVE-2012-3991
- EPSS 1.42%
- Veröffentlicht 10.10.2012 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which allows remote attackers to by...
- EPSS 4.55%
- Veröffentlicht 29.08.2012 10:56:41
- Zuletzt bearbeitet 11.04.2025 00:51:21
The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to obtain sensit...
CVE-2012-3976
- EPSS 0.78%
- Veröffentlicht 29.08.2012 10:56:41
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoof the X.509 certificate inform...
- EPSS 3.31%
- Veröffentlicht 29.08.2012 10:56:40
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the gfxTextRun::CanBreakLineBefore function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers...
- EPSS 3.31%
- Veröffentlicht 29.08.2012 10:56:40
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the PresShell::CompleteMove function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to exe...
- EPSS 3.17%
- Veröffentlicht 29.08.2012 10:56:40
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the nsHTMLSelectElement::SubmitNamesValues function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote a...