Oval Definition:oval:org.mitre.oval:def:11887
Revision Date:2014-10-06Version:28
Title:Mozilla Firefox and Thunderbird Same-origin Bypass Using Canvas Context Vulnerability
Description:Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node deletion.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2010-1207
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Mozilla Firefox
Mozilla Thunderbird
Definition Synopsis
  • Check for vulnerable Firefox mainline
  • Mozilla Firefox Mainline release is installed
  • AND Check for vulnerable version
  • Mozilla Firefox Mainline version is 3.6.x before 3.6.7
  • OR Check for vulnerable Thunderbird Mainline
  • Mozilla Thunderbird Mainline release is installed
  • AND Mozilla Thunderbird 3.1.x before 3.1.1
  • BACK