CVE-2012-3984
published 2012-10-10CVE-2012-3984: Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has a SELECT…
PriorityP427medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.25%
80.9th percentile
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has a SELECT element's menu active, which allows remote attackers to spoof page content via vectors involving absolute positioning and scrolling.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| mozilla | firefox | < 16.0 | 16.0 |
| mozilla | seamonkey | < 2.13 | 2.13 |
| mozilla | thunderbird | < 16.0 | 16.0 |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_ubuntu9.3CRITICAL
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-crp5-x6hq-7qw3: Mozilla Firefox before 16
ghsa_unreviewed·2022-05-13·CVSS 6.8
CVE-2012-5354 [MEDIUM] GHSA-crp5-x6hq-7qw3: Mozilla Firefox before 16
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has multiple menus of SELECT elements active, which allows remote attackers to conduct clickjacking attacks via vectors involving an XPI file, the window.open method, and the Geolocation API, a different vulnerability than CVE-2012-3984.
GHSA
GHSA-m3hq-4m6f-jcr6: Mozilla Firefox before 16
ghsa_unreviewed·2022-05-13
CVE-2012-3984 [MEDIUM] GHSA-m3hq-4m6f-jcr6: Mozilla Firefox before 16
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has a SELECT element's menu active, which allows remote attackers to spoof page content via vectors involving absolute positioning and scrolling.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2012-10-12·CVSS 9.3
CVE-2012-3982 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others
discovered several memory corruption flaws in Thunderbird. If a user were
tricked into opening a malicious website and had JavaScript enabled, an
attacker could exploit these to execute arbitrary JavaScript code within
the context of another website or arbitrary code as the user invoking the
program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,
CVE-2012-4191)
David Bloom and Jordi Chancel discovered that Thunderbird did not always
properly handle the element. If a user were tricked into opening a
malicious website and had JavaScript enabled, a remote attacker could
exploit this to conduct URL spoofing an
Red Hat
Mozilla: Select element persistance allows for attacks (MFSA 2012-75)
vendor_redhat·2012-10-09·CVSS 6.8
CVE-2012-3984 [MEDIUM] Mozilla: Select element persistance allows for attacks (MFSA 2012-75)
Mozilla: Select element persistance allows for attacks (MFSA 2012-75)
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has a SELECT element's menu active, which allows remote attackers to spoof page content via vectors involving absolute positioning and scrolling.
Statement: Not vulnerable. This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Red Hat
Mozilla: Select element persistance allows for attacks (MFSA 2012-75)
vendor_redhat·2012-10-09·CVSS 6.8
CVE-2012-5354 [MEDIUM] Mozilla: Select element persistance allows for attacks (MFSA 2012-75)
Mozilla: Select element persistance allows for attacks (MFSA 2012-75)
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has multiple menus of SELECT elements active, which allows remote attackers to conduct clickjacking attacks via vectors involving an XPI file, the window.open method, and the Geolocation API, a different vulnerability than CVE-2012-3984.
Statement: Not vulnerable. This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunder
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2012-10-09·CVSS 9.3
CVE-2012-3983 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Multiple security issues were fixed in Firefox.
Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others
discovered several memory corruption flaws in Firefox. If a user were
tricked into opening a specially crafted web page, a remote attacker could
cause Firefox to crash or potentially execute arbitrary code as the user
invoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,
CVE-2012-3989)
David Bloom and Jordi Chancel discovered that Firefox did not always
properly handle the element. A remote attacker could exploit this
to conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)
Collin Jackson discovered that Firefox did not properly follow the HTML5
specification for document.domain behavior. A remote attac
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3984 CVE-2012-5354 Mozilla: Select element persistance allows for attacks (MFSA 2012-75)
bugzilla·2012-10-06·CVSS 6.8
CVE-2012-3984 [MEDIUM] CVE-2012-3984 CVE-2012-5354 Mozilla: Select element persistance allows for attacks (MFSA 2012-75)
CVE-2012-3984 CVE-2012-5354 Mozilla: Select element persistance allows for attacks (MFSA 2012-75)
Security researcher David Bloom of Cue discovered that elements are always-on-top chromeless windows and that navigation away from a page with an active menu does not remove this window.When another menu is opened programmatically on a new page, the original menu can be retained and arbitrary HTML content within it rendered, allowing an attacker to cover arbitrary portions of the new page through absolute positioning/scrolling, leading to spoofing attacks. Security researcher Jordi Chancel found a variation that would allow for click-jacking attacks was well.
In general these flaws cannot be exploited through email in the Thunderbird and SeaMonkey products because scripting is disabled, but
Bugzilla
(CVE-2012-3984) Firefox 10.0.1 : Navigation away from a page with multiple active <select> dropdown menu can be used for Spoofing And ClickJacking with XPI using window.open and geolocalisation
bugzilla·2012-02-11·CVSS 6.8
CVE-2012-3984 [MEDIUM] (CVE-2012-3984) Firefox 10.0.1 : Navigation away from a page with multiple active <select> dropdown menu can be used for Spoofing And ClickJacking with XPI using window.open and geolocalisation
(CVE-2012-3984) Firefox 10.0.1 : Navigation away from a page with multiple active dropdown menu can be used for Spoofing And ClickJacking with XPI using window.open and geolocalisation
Created attachment 596272
TESTCASE.ZIP
User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.1) Gecko/20100101 Firefox/10.0.1
Build ID: 20120208060813
Steps to reproduce:
Like bug 575294 , Firefox 10.0.1 shows the dropdown menu for elements as an always-on-top chromeless window. It also allows arbitrary HTML content to be rendered in the elements within the .
Actual results:
This bug demonstrates than an attacker can cover a XPI for evil.
I think this issue is critical.
Discussion:
this issue works only if a user disabled the pop-up blocker or allowed pop-ups for this site.
---
Created attachme
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.htmlhttp://secunia.com/advisories/50856http://secunia.com/advisories/50892http://secunia.com/advisories/50904http://secunia.com/advisories/50935http://secunia.com/advisories/50984http://www.mozilla.org/security/announce/2012/mfsa2012-75.htmlhttp://www.ubuntu.com/usn/USN-1611-1https://bugzilla.mozilla.org/show_bug.cgi?id=575294https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16184http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.htmlhttp://secunia.com/advisories/50856http://secunia.com/advisories/50892http://secunia.com/advisories/50904http://secunia.com/advisories/50935http://secunia.com/advisories/50984http://www.mozilla.org/security/announce/2012/mfsa2012-75.htmlhttp://www.ubuntu.com/usn/USN-1611-1https://bugzilla.mozilla.org/show_bug.cgi?id=575294https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16184
2012-10-10
Published