CVE-2012-3976

Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoof the X.509 certificate information in the address bar via a crafted web page.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
VendorProductVersion
mozillafirefox
𝑥
< 15.0
mozillafirefox
10.0 ≤
𝑥
< 10.0.7
mozillaseamonkey
𝑥
< 2.12
opensuseopensuse
12.2
redhatenterprise_linux_desktop
5.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_eus
6.3
redhatenterprise_linux_server
5.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server_eus
6.3
redhatenterprise_linux_workstation
5.0
redhatenterprise_linux_workstation
6.0
canonicalubuntu_linux
10.04
canonicalubuntu_linux
11.04
canonicalubuntu_linux
11.10
canonicalubuntu_linux
12.04
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
saucy
Fixed 15.0+build1-0ubuntu1
released
raring
Fixed 15.0+build1-0ubuntu1
released
quantal
Fixed 15.0+build1-0ubuntu1
released
precise
Fixed 15.0+build1-0ubuntu0.12.04.1
released
oneiric
Fixed 15.0+build1-0ubuntu0.11.10.1
released
natty
Fixed 15.0+build1-0ubuntu0.11.04.2
released
lucid
Fixed 15.0+build1-0ubuntu0.10.04.1
released
hardy
ignored
seamonkey
saucy
dne
raring
dne
quantal
dne
precise
dne
oneiric
ignored
natty
ignored
lucid
ignored
hardy
ignored
thunderbird
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
lucid
not-affected
hardy
ignored
xulrunner-1.9.2
saucy
dne
raring
dne
quantal
dne
precise
dne
oneiric
dne
natty
ignored
lucid
ignored
hardy
ignored
xulrunner-2.0
saucy
dne
raring
dne
quantal
dne
precise
dne
oneiric
dne
natty
ignored
lucid
dne
hardy
dne