CVE-2012-0460: Medium severity firefox vulnerability
Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict write access to the window.fullScreen object, which allows remote attackers to spoof the user interface via a crafted web page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0460?
CVE-2012-0460 has a medium severity rating due to its potential for UI spoofing.
How do I fix CVE-2012-0460?
To fix CVE-2012-0460, upgrade your Mozilla Firefox, Thunderbird, or SeaMonkey application to the latest version that addresses this vulnerability.
Which versions are affected by CVE-2012-0460?
CVE-2012-0460 affects Mozilla Firefox versions 4.x to 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8.
What type of vulnerability is CVE-2012-0460?
CVE-2012-0460 is a UI spoofing vulnerability that allows attackers to manipulate the user interface via the window.fullScreen object.
Who is primarily affected by CVE-2012-0460?
Users of Mozilla Firefox, Thunderbird, and SeaMonkey versions outlined in the CVE-2012-0460 report are primarily affected.