First published: Wed Jun 11 2014(Updated: )
Mozilla Firefox before 30.0 and Thunderbird through 24.6 on OS X do not ensure visibility of the cursor after interaction with a Flash object and a DIV element, which makes it easier for remote attackers to conduct clickjacking attacks via JavaScript code that produces a fake cursor image.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=29.0.1 | |
Mozilla Thunderbird | <=24.6 | |
Mozilla Thunderbird | =24.0 | |
Mozilla Thunderbird | =24.0.1 | |
Mozilla Thunderbird | =24.1 | |
Mozilla Thunderbird | =24.1.1 | |
Mozilla Thunderbird | =24.2 | |
Mozilla Thunderbird | =24.3 | |
Mozilla Thunderbird | =24.4 | |
Mozilla Thunderbird | =24.5 | |
Apple Mac OS X |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.