Mozilla Firefox/Thunderbird/SeaMonkey Multiple HTML Injection Vulnerabilities
29 Dec. 2011
Summary
Mozilla Firefox, SeaMonkey, and Thunderbird are prone to multiple HTML-injection vulnerabilities.
Credit:
The original article can be found at: http://www.securityfocus.com/bid/45353
The information has been provided by Yosuke Hasegawa, Masatoshi Kimura
Vulnerable Systems:
* Mozilla SeaMonkey 2.0.9
* Mozilla SeaMonkey 2.0.8
* Mozilla SeaMonkey 2.0.5
* Mozilla SeaMonkey 2.0.4
* Mozilla SeaMonkey 2.0.3
* Mozilla SeaMonkey 2.0.2
* Mozilla SeaMonkey 2.0.1
* Mozilla SeaMonkey 2.0.9
* Mozilla SeaMonkey 2.0.7
* Mozilla SeaMonkey 2.0.6
* Mozilla SeaMonkey 2.0.5
* Mozilla SeaMonkey 2.0.4
* Mozilla SeaMonkey 2.0.10
* Mozilla SeaMonkey 2.0 Rc2
* Mozilla SeaMonkey 2.0 Rc1
* Mozilla SeaMonkey 2.0 Beta 2
* Mozilla SeaMonkey 2.0 Beta 1
* Mozilla SeaMonkey 2.0 Alpha 3
* Mozilla SeaMonkey 2.0 Alpha 2
* Mozilla SeaMonkey 2.0 Alpha 1
* Mozilla SeaMonkey 2.0
* Mozilla Firefox 3.6.10
* Mozilla Firefox 3.6.9
* Mozilla Firefox 3.6.8
* Mozilla Firefox 3.6.6
* Mozilla Firefox 3.6.4
* Mozilla Firefox 3.6.3
* Mozilla Firefox 3.6.2
* Mozilla Firefox 3.6.2
* Mozilla Firefox 3.5.17
* Mozilla Firefox 3.5.14
* Mozilla Firefox 3.5.13
* Mozilla Firefox 3.5.10
* Mozilla Firefox 3.5.10
* Mozilla Firefox 3.5.9
* Mozilla Firefox 3.5.9
* Mozilla Firefox 3.5.8
* Mozilla Firefox 3.5.7
* Mozilla Firefox 3.5.6
* Mozilla Firefox 3.5.5
* Mozilla Firefox 3.5.4
* Mozilla Firefox 3.5.3
* Mozilla Firefox 3.5.2
* Mozilla Firefox 3.5.1
* Mozilla Firefox 3.5
* Mozilla Firefox 3.6.7
* Mozilla Firefox 3.6.6
* Mozilla Firefox 3.6.12
* Mozilla Firefox 3.6.11
* Mozilla Firefox 3.6 Beta 3
* Mozilla Firefox 3.6 Beta 2
* Mozilla Firefox 3.6
* Mozilla Firefox 3.5.15
* Mozilla Firefox 3.5.12
* Mozilla Firefox 3.5.11
Non-Vulnerable Systems:
* Mozilla SeaMonkey 2.0.11
* Mozilla Firefox 3.6.13
* Mozilla Firefox 3.5.16
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Vendor Status:
Mozilla as issued an update for this vulnerablity