CVE-2002-2437: Medium severity firefox vulnerability
The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2437?
CVE-2002-2437 is considered a moderate severity vulnerability due to its potential for exposing sensitive information.
How do I fix CVE-2002-2437?
To mitigate CVE-2002-2437, upgrade to a version of Mozilla Firefox, Thunderbird, or SeaMonkey that is patched or less than version 4.0.
What systems are affected by CVE-2002-2437?
CVE-2002-2437 affects Mozilla Firefox versions before 4.0, Thunderbird versions before 3.3, and SeaMonkey versions before 2.1.
What type of vulnerability is CVE-2002-2437?
CVE-2002-2437 is a data exposure vulnerability that allows remote attackers to access sensitive information through the getComputedStyle method.
Is CVE-2002-2437 actively being exploited?
There have been no recent reports of CVE-2002-2437 being actively exploited, but it remains a vulnerability that should be addressed.