CVE-2012-3986: Input Validation
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils) methods, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3986?
CVE-2012-3986 has been classified as a moderate severity vulnerability.
How do I fix CVE-2012-3986?
To fix CVE-2012-3986, update your Mozilla Firefox, Thunderbird, or SeaMonkey to the latest version.
Which software is affected by CVE-2012-3986?
CVE-2012-3986 affects Mozilla Firefox, Thunderbird, Thunderbird ESR, and SeaMonkey versions prior to specified release versions.
Can CVE-2012-3986 be exploited remotely?
Yes, CVE-2012-3986 can be exploited remotely by attackers to bypass access restrictions.
Is there a workaround for CVE-2012-3986?
There are currently no official workarounds for CVE-2012-3986 other than applying the necessary updates.