9.3
CVSSv2

CVE-2012-3989

Published: 10/10/2012 Updated: 27/08/2020
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Mozilla Firefox prior to 16.0, Thunderbird prior to 16.0, and SeaMonkey prior to 2.13 do not properly perform a cast of an unspecified variable during use of the instanceof operator on a JavaScript object, which allows remote malicious users to execute arbitrary code or cause a denial of service (assertion failure) via a crafted web site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla seamonkey

mozilla thunderbird

canonical ubuntu linux 10.04

canonical ubuntu linux 11.04

canonical ubuntu linux 11.10

canonical ubuntu linux 12.04

suse linux enterprise desktop 10

suse linux enterprise desktop 11

suse linux enterprise server 10

suse linux enterprise server 11

Vendor Advisories

Multiple security issues were fixed in Firefox ...
Several security issues were fixed in Thunderbird ...
Mozilla Foundation Security Advisory 2012-80 Crash with invalid cast when using instanceof operator Announced October 9, 2012 Reporter Ms2ger Impact Critical Products Firefox, SeaMonkey, Thunderbird Fixed in ...