CVE-2012-0479: Medium severity firefox vulnerability
Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to spoof the address bar via an https URL for invalid (1) RSS or (2) Atom XML content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0479?
CVE-2012-0479 has been classified as a moderate severity vulnerability.
How do I fix CVE-2012-0479?
To fix CVE-2012-0479, update to the latest version of Mozilla Firefox, Thunderbird, or SeaMonkey.
Which versions are affected by CVE-2012-0479?
CVE-2012-0479 affects Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey versions before 2.9.
What type of vulnerability is CVE-2012-0479?
CVE-2012-0479 is a spoofing vulnerability that allows attackers to display a misleading address in the browser's address bar.
Can I still use an affected version of Firefox with CVE-2012-0479?
Using an affected version of Firefox, Thunderbird, or SeaMonkey poses a security risk, and it is recommended to upgrade to a patched version.