Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-5354
HistoryOct 10, 2012 - 12:00 a.m.

CVE-2012-5354

2012-10-1000:00:00
ubuntu.com
ubuntu.com
10

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.013 Low

EPSS

Percentile

85.9%

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before
2.13 do not properly handle navigation away from a web page that has
multiple menus of SELECT elements active, which allows remote attackers to
conduct clickjacking attacks via vectors involving an XPI file, the
window.open method, and the Geolocation API, a different vulnerability than
CVE-2012-3984.

OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchfirefox< 16.0+build1-0ubuntu0.10.04.1UNKNOWN
ubuntu11.04noarchfirefox< 16.0+build1-0ubuntu0.11.04.1UNKNOWN
ubuntu11.10noarchfirefox< 16.0+build1-0ubuntu0.11.10.1UNKNOWN
ubuntu12.04noarchfirefox< 16.0+build1-0ubuntu0.12.04.1UNKNOWN
ubuntu12.10noarchfirefox< 16.0+build1-0ubuntu1UNKNOWN
ubuntu13.04noarchfirefox< 16.0+build1-0ubuntu1UNKNOWN
ubuntu13.10noarchfirefox< 16.0+build1-0ubuntu1UNKNOWN
ubuntu10.04noarchthunderbird< 16.0+build1-0ubuntu0.10.04.1UNKNOWN
ubuntu11.04noarchthunderbird< 16.0+build1-0ubuntu0.11.04.1UNKNOWN
ubuntu11.10noarchthunderbird< 16.0+build1-0ubuntu0.11.10.1UNKNOWN
Rows per page:
1-10 of 141

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.013 Low

EPSS

Percentile

85.9%