Oval Definition:oval:org.mitre.oval:def:15122
Revision Date:2014-10-06Version:33
Title:Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict setting the home page through the dragging of a URL to the home button, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a javascript: URL that is later interpreted in the about:sessionrestore context.
Description:Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict setting the home page through the dragging of a URL to the home button, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a javascript: URL that is later interpreted in the about:sessionrestore context.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2012-0458
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Mozilla Firefox
Mozilla Firefox ESR
Mozilla Seamonkey
Mozilla Thunderbird
Mozilla Thunderbird ESR
Definition Synopsis
  • Determine if the version of Mozilla Firefox is less than or equal to 3.6.27 and is greater than or equal to 3.0.1
  • Mozilla Firefox Mainline release is installed
  • AND Mozilla Firefox Mainline version is less than or equal to 3.6.27
  • AND Check for vulnerable version
  • Mozilla Firefox Mainline version is greater than or equal to 3.0.1
  • OR Determine if the version of Mozilla Firefox is less than or equal to 2.10 and is greater than or equal to 2.0.0.1
  • Mozilla Firefox Mainline release is installed
  • AND Mozilla Firefox Mainline version is less than or equal to 2.10
  • AND Check for vulnerable version
  • Mozilla Firefox Mainline version is greater than or equal to 2.0.0.1
  • OR Determine if the version of Mozilla Firefox is less than or equal to 1.8 and is greater than or equal to 1.0.1
  • Mozilla Firefox Mainline release is installed
  • AND Mozilla Firefox Mainline version is less than or equal to 1.8
  • AND Mozilla Firefox Mainline version is greater than or equal to 1.0.1
  • OR Determine if the version of Mozilla Firefox is equal to 4.0
  • Mozilla Firefox Mainline release is installed
  • AND Check for vulnerable version
  • Mozilla Firefox Mainline version is equal to 4.0
  • OR Determine if the version of Mozilla Firefox is equal to 5.0.1
  • Mozilla Firefox Mainline release is installed
  • AND Mozilla Firefox Mainline version is equal to 5.0.1
  • OR Determine if the version of Mozilla Firefox is less than or equal to 6.0.2 and is greater than or equal to 6.0.1
  • Mozilla Firefox Mainline release is installed
  • AND Mozilla Firefox Mainline version is less than or equal to 6.0.2
  • AND Mozilla Firefox Mainline version is greater than or equal to 6.0.1
  • OR Determine if the version of Mozilla Firefox is equal to 7.0.1
  • Mozilla Firefox Mainline release is installed
  • AND Check for vulnerable version
  • Mozilla Firefox Mainline version is equal to 7.0.1
  • OR Determine if the version of Mozilla Firefox is equal to 8.0
  • Mozilla Firefox Mainline release is installed
  • AND Mozilla Firefox Mainline version is equal to 8.0
  • OR Determine if the version of Mozilla Firefox is equal to 9.0.1
  • Mozilla Firefox Mainline release is installed
  • AND Mozilla Firefox Mainline version is equal to 9.0.1
  • OR Determine if the version of Mozilla Thunderbird is less than or equal to 3.1.19 and is greater than or equal to 3.0
  • Mozilla Thunderbird Mainline release is installed
  • AND Determine if the version of Mozilla Thunderbird is less than or equal to 3.1.19
  • AND Determine if the version of Mozilla Thunderbird is greater than or equal to 3.0
  • OR Determine if the version of Mozilla Thunderbird is less than or equal to 2.14 and is greater than or equal to 2.0.0.0
  • Mozilla Thunderbird Mainline release is installed
  • AND Determine if the version of Mozilla Thunderbird is less than or equal to 2.14
  • AND Determine if the version of Mozilla Thunderbird is greater than or equal to 2.0.0.0
  • OR Determine if the version of Mozilla Thunderbird is less than or equal to 1.7.3 and is greater than or equal to 1.0.1
  • Mozilla Thunderbird Mainline release is installed
  • AND Determine if the version of Mozilla Thunderbird is less than or equal to 1.7.3
  • AND Determine if the version of Mozilla Thunderbird is greater than or equal to 1.0.1
  • OR Determine if the version of Mozilla Thunderbird is equal to 5.0
  • Mozilla Thunderbird Mainline release is installed
  • AND Determine if the version of Mozilla Thunderbird is equal to 5.0
  • OR Determine if the version of Mozilla Thunderbird is equal to 6.0
  • Mozilla Thunderbird Mainline release is installed
  • AND Determine if the version of Mozilla Thunderbird is equal to 6.0
  • OR Determine if the version of Mozilla Thunderbird is equal to 8.0
  • Mozilla Thunderbird Mainline release is installed
  • AND Determine if the version of Mozilla Thunderbird is equal to 8.0
  • OR Determine if the version of Mozilla Thunderbird is equal to 9.0.1
  • Mozilla Thunderbird Mainline release is installed
  • AND Determine if the version of Mozilla Thunderbird is equal to 9.0.1
  • OR Determine if the version of Mozilla Seamonkey is less than or equal to 2.7 and is greater than or equal to 2.0.1
  • Mozilla Seamonkey is installed
  • AND Determine if the version of Mozilla Seamonkey is less than or equal to 2.7
  • AND Determine if the version of Mozilla Seamonkey is greater than or equal to 2.0.1
  • OR Determine if the version of Mozilla Seamonkey is less than or equal to 1.5.0.10 and is greater than or equal to 1.0
  • Mozilla Seamonkey is installed
  • AND Determine if the version of Mozilla Seamonkey is less than or equal to 1.5.0.10
  • AND Determine if the version of Mozilla Seamonkey is greater than or equal to 1.0
  • OR Check for vulnerable Mozilla Firefox ESR
  • Mozilla Firefox ESR is installed
  • AND Mozilla Firefox ESR version is less than 10.0.3 and greater than or equal to 10.x
  • OR Check for vulnerable Mozilla Thunderbird ESR
  • Mozilla Thunderbird ESR is installed
  • AND Mozilla Thunderbird ESR version is less than 10.0.3 and greater than or equal to 10.x
  • BACK