First published: Wed Dec 07 2011(Updated: )
The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | =3.6.2 | |
Firefox | =3.0.17 | |
Firefox | =3.5.3 | |
Firefox | =3.0.7 | |
Firefox | =3.0.9 | |
Firefox | =3.6.3 | |
Firefox | =3.5.6 | |
Firefox | =3.0.8 | |
Firefox | =3.5 | |
Firefox | =3.5.5 | |
Firefox | =3.0.4 | |
Firefox | =3.5.9 | |
Firefox | =3.5.4 | |
Firefox | =3.5.7 | |
Firefox | =3.0.5 | |
Firefox | =3.5.11 | |
Firefox | =3.5.14 | |
Firefox | =3.6.15 | |
Firefox | =3.5.10 | |
Firefox | =3.5.1 | |
Firefox | =3.0.14 | |
Firefox | =3.5.2 | |
Firefox | =3.6.17 | |
Firefox | <=3.6.24 | |
Firefox | =3.6.11 | |
Firefox | =3.6.8 | |
Firefox | =3.0.10 | |
Firefox | =3.6.9 | |
Firefox | =3.6.14 | |
Firefox | =3.0.12 | |
Firefox | =3.0.3 | |
Firefox | =3.6.12 | |
Firefox | =3.6.23 | |
Firefox | =3.0.6 | |
Firefox | =3.0.15 | |
Firefox | =3.5.12 | |
Firefox | =3.6.6 | |
Firefox | =3.0 | |
Firefox | =3.6.21 | |
Firefox | =3.6.16 | |
Firefox | =3.0.1 | |
Firefox | =3.6.1 | |
Firefox | =3.6.10 | |
Firefox | =3.6.19 | |
Firefox | =3.5.13 | |
Firefox | =3.0.2 | |
Firefox | =3.5.8 | |
Firefox | =3.6.7 | |
Firefox | =3.6.4 | |
Firefox | =3.6.18 | |
Firefox | =3.5.15 | |
Firefox | =3.6.20 | |
Firefox | =3.6 | |
Firefox | =3.6.22 | |
Firefox | =3.6.13 | |
Firefox | =3.0.13 | |
Firefox | =3.0.16 | |
Firefox | =3.0.11 | |
Thunderbird | =3.0.8 | |
Thunderbird | =3.0.5 | |
Thunderbird | =3.1.8 | |
Thunderbird | =3.1.11 | |
Thunderbird | =3.0.9 | |
Thunderbird | =3.0.1 | |
Thunderbird | =3.1.14 | |
Thunderbird | =3.1.7 | |
Thunderbird | =3.1.2 | |
Thunderbird | =3.1.9 | |
Thunderbird | =3.1.1 | |
Thunderbird | =3.1.15 | |
Thunderbird | =3.1.4 | |
Thunderbird | =3.0.7 | |
Thunderbird | =3.0.6 | |
Thunderbird | =3.0.10 | |
Thunderbird | =3.0.3 | |
Thunderbird | =3.1.5 | |
Thunderbird | =3.0.11 | |
Thunderbird | =3.1.10 | |
Thunderbird | <=3.1.16 | |
Thunderbird | =3.0.4 | |
Thunderbird | =3.1.13 | |
Thunderbird | =3.0 | |
Thunderbird | =3.1 | |
Thunderbird | =3.1.3 | |
Thunderbird | =3.1.6 | |
Thunderbird | =3.1.12 | |
Thunderbird | =3.0.2 | |
Mozilla SeaMonkey | =2.0.10 | |
Mozilla SeaMonkey | =1.1.10 | |
Mozilla SeaMonkey | =1.0.3 | |
Mozilla SeaMonkey | =2.0.13 | |
Mozilla SeaMonkey | =1.1.8 | |
Mozilla SeaMonkey | =1.0.1 | |
Mozilla SeaMonkey | =1.1.7 | |
Mozilla SeaMonkey | =1.5.0.10 | |
Mozilla SeaMonkey | =1.0.6 | |
Mozilla SeaMonkey | =1.0.9 | |
Mozilla SeaMonkey | =1.1.3 | |
Mozilla SeaMonkey | =2.0.4 | |
Mozilla SeaMonkey | =1.0 | |
Mozilla SeaMonkey | =2.1-alpha2 | |
Mozilla SeaMonkey | =2.0.3 | |
Mozilla SeaMonkey | =2.0.2 | |
Mozilla SeaMonkey | =1.1.17 | |
Mozilla SeaMonkey | =2.0-alpha_2 | |
Mozilla SeaMonkey | =1.1.5 | |
Mozilla SeaMonkey | =2.0.8 | |
Mozilla SeaMonkey | =1.0.7 | |
Mozilla SeaMonkey | =1.0-beta | |
Mozilla SeaMonkey | =1.1-alpha | |
Mozilla SeaMonkey | =2.0-rc2 | |
Mozilla SeaMonkey | =2.0-alpha_3 | |
Mozilla SeaMonkey | =1.0-alpha | |
Mozilla SeaMonkey | =2.0a1 | |
Mozilla SeaMonkey | =1.1.12 | |
Mozilla SeaMonkey | =2.0.12 | |
Mozilla SeaMonkey | =1.1 | |
Mozilla SeaMonkey | =1.1.14 | |
Mozilla SeaMonkey | =2.0.11 | |
Mozilla SeaMonkey | =1.1.2 | |
Mozilla SeaMonkey | =2.0-beta_2 | |
Mozilla SeaMonkey | =1.0.2 | |
Mozilla SeaMonkey | =1.0.8 | |
Mozilla SeaMonkey | =1.1.11 | |
Mozilla SeaMonkey | =2.0-alpha_1 | |
Mozilla SeaMonkey | =1.5.0.9 | |
Mozilla SeaMonkey | =1.1-beta | |
Mozilla SeaMonkey | =1.1.1 | |
Mozilla SeaMonkey | <=2.1 | |
Mozilla SeaMonkey | =2.0.9 | |
Mozilla SeaMonkey | =2.1-alpha1 | |
Mozilla SeaMonkey | =1.5.0.8 | |
Mozilla SeaMonkey | =2.0.1 | |
Mozilla SeaMonkey | =1.0.5 | |
Mozilla SeaMonkey | =1.1.15 | |
Mozilla SeaMonkey | =2.0.14 | |
Mozilla SeaMonkey | =1.1.6 | |
Mozilla SeaMonkey | =2.0.7 | |
Mozilla SeaMonkey | =1.1.16 | |
Mozilla SeaMonkey | =2.0-beta_1 | |
Mozilla SeaMonkey | =1.1.19 | |
Mozilla SeaMonkey | =2.0.5 | |
Mozilla SeaMonkey | =2.0-rc1 | |
Mozilla SeaMonkey | =1.0.4 | |
Mozilla SeaMonkey | =1.1.9 | |
Mozilla SeaMonkey | =1.1.13 | |
Mozilla SeaMonkey | =1.1.18 | |
Mozilla SeaMonkey | =2.0.6 | |
Mozilla SeaMonkey | =2.0 | |
Mozilla SeaMonkey | =1.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2437 is considered a moderate severity vulnerability due to its potential for exposing sensitive information.
To mitigate CVE-2002-2437, upgrade to a version of Mozilla Firefox, Thunderbird, or SeaMonkey that is patched or less than version 4.0.
CVE-2002-2437 affects Mozilla Firefox versions before 4.0, Thunderbird versions before 3.3, and SeaMonkey versions before 2.1.
CVE-2002-2437 is a data exposure vulnerability that allows remote attackers to access sensitive information through the getComputedStyle method.
There have been no recent reports of CVE-2002-2437 being actively exploited, but it remains a vulnerability that should be addressed.