Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
Mozilla Products Certificate Page Clickjacking Vulnerability (Mac OS X)
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
This host is installed with Mozilla firefox/thunderbird/seamonkey and is prone to clickjacking vulnerability.
Insight
Insight
The certificate warning functionality in browser/components/certerror/content/aboutCertError.xhtml fails to handle attempted clickjacking of the 'about:certerror' page, allowing man-in-the-middle attackers to trick users into adding an unintended exception via an IFRAME element
Affected Software
Affected Software
SeaMonkey version before 2.10 Thunderbird version 5.0 through 12.0 Mozilla Firefox version 4.x through 12.0 Thunderbird ESR version 10.x before 10.0.6 Mozilla Firefox ESR version 10.x before 10.0.6 on Mac OS X
Solution
Solution
Upgrade to Mozilla Firefox version 14.0 or ESR version 10.0.6 or later. Upgrade to SeaMonkey version to 2.11 or later. Upgrade to Thunderbird version to 14.0 or ESR 10.0.6 or later.