Lucene search

K
mozillaMozilla FoundationMFSA2012-17
HistoryMar 13, 2012 - 12:00 a.m.

Crash when accessing keyframe cssText after dynamic modification — Mozilla

2012-03-1300:00:00
Mozilla Foundation
www.mozilla.org
26

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.152

Percentile

96.0%

Mozilla community member Daniel Glazman of Disruptive Innovations reported a crash when accessing a keyframe’s cssText after dynamic modification. This crash may be potentially exploitable.

Affected configurations

Vulners
Node
mozillafirefoxRange<11
OR
mozillafirefox_esrRange<10.0.3
OR
mozillaseamonkeyRange<2.8
OR
mozillathunderbirdRange<11
OR
mozillathunderbird_esrRange<10.0.3
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillafirefox_esr*cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
mozillathunderbird_esr*cpe:2.3:a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.152

Percentile

96.0%