299,584
Total vulnerabilities in the database
Mozilla Firefox before 30.0 and Thunderbird through 24.6 on OS X do not ensure visibility of the cursor after interaction with a Flash object and a DIV element, which makes it easier for remote attackers to conduct clickjacking attacks via JavaScript code that produces a fake cursor image.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 29.0.1.x |
| mozilla / thunderbird | - | 24.6.x |
| mozilla / thunderbird | 24.0 | 24.0.x |
| mozilla / thunderbird | 24.0.1 | 24.0.1.x |
| mozilla / thunderbird | 24.1 | 24.1.x |
| mozilla / thunderbird | 24.1.1 | 24.1.1.x |
| mozilla / thunderbird | 24.2 | 24.2.x |
| mozilla / thunderbird | 24.3 | 24.3.x |
| mozilla / thunderbird | 24.4 | 24.4.x |
| mozilla / thunderbird | 24.5 | 24.5.x |