SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-0460

Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict write access to the window.fullScreen object, which allows remote…

MEDIUM 6.4EPSS 2.00%

Does this matter?

Lower severity and a low EPSS score (2.00%). Track it; it rarely justifies an emergency change on its own.

Description

Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict write access to the window.fullScreen object, which allows remote attackers to spoof the user interface via a crafted web page.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
EPSS
2.00% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
mozilla/firefox · mozilla/firefox esr · mozilla/thunderbird · mozilla/thunderbird esr · mozilla/seamonkey
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.