CVE-2012-3976
published 2012-08-29CVE-2012-3976: Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.78%
75.8th percentile
Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoof the X.509 certificate information in the address bar via a crafted web page.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| mozilla | firefox | < 15.0 | 15.0 |
| mozilla | firefox | >= 10.0 < 10.0.7 | 10.0.7 |
| mozilla | seamonkey | < 2.12 | 2.12 |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-42j4-67r4-889f: Mozilla Firefox before 15
ghsa_unreviewed·2022-05-13
CVE-2012-3976 [MEDIUM] CWE-200 GHSA-42j4-67r4-889f: Mozilla Firefox before 15
Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoof the X.509 certificate information in the address bar via a crafted web page.
Ubuntu
Firefox regression
vendor_ubuntu·2012-09-11·CVSS 4.3
[MEDIUM] Firefox regression
Title: Firefox regression
Summary: USN-1548-1 introduced a regression in Firefox.
USN-1548-1 fixed vulnerabilities in Firefox. The new package caused a
regression in Private Browsing which could leak sites visited to the
browser cache. This update fixes the problem.
Original advisory details:
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Firefox. If the user were
tricked into opening a specially crafted page, an attacker could exploit
these to cause a denial of service via application crash, or potentially
execute code with the privileges of the user invoking Firefox.
(CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discovered multiple use-
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2012-08-29·CVSS 4.3
CVE-2012-1970 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Multiple security issues were fixed in Firefox.
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Firefox. If the user were
tricked into opening a specially crafted page, an attacker could exploit
these to cause a denial of service via application crash, or potentially
execute code with the privileges of the user invoking Firefox.
(CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discovered multiple use-after-free vulnerabilities. If the
user were tricked into opening a specially crafted page, an attacker could
exploit these to cause a denial of service via application crash, or
potentially execute code with
Red Hat
Mozilla: Incorrect site SSL certificate data display (MFSA 2012-69)
vendor_redhat·2012-08-28·CVSS 4.3
CVE-2012-3976 [MEDIUM] Mozilla: Incorrect site SSL certificate data display (MFSA 2012-69)
Mozilla: Incorrect site SSL certificate data display (MFSA 2012-69)
Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoof the X.509 certificate information in the address bar via a crafted web page.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1210.htmlhttp://www.mozilla.org/security/announce/2012/mfsa2012-69.htmlhttp://www.securityfocus.com/bid/55313http://www.ubuntu.com/usn/USN-1548-1http://www.ubuntu.com/usn/USN-1548-2http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfhttps://bugzilla.mozilla.org/show_bug.cgi?id=768568https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16060http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1210.htmlhttp://www.mozilla.org/security/announce/2012/mfsa2012-69.htmlhttp://www.securityfocus.com/bid/55313http://www.ubuntu.com/usn/USN-1548-1http://www.ubuntu.com/usn/USN-1548-2http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfhttps://bugzilla.mozilla.org/show_bug.cgi?id=768568https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16060
2012-08-29
Published