CVE-2002-2437

Firefox < 4.0 - Information Disclosure via getComputedStyle Method

Title source: llm
STIX 2.1

Description

The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.

References (4)

Core 4

Scores

EPSS 0.0133
EPSS Percentile 68.0%

Details

CWE
CWE-264
Status published
Products (50)
mozilla/firefox 3.0
mozilla/firefox 3.0.1
mozilla/firefox 3.0.2
mozilla/firefox 3.0.3
mozilla/firefox 3.0.4
mozilla/firefox 3.0.5
mozilla/firefox 3.0.6
mozilla/firefox 3.0.7
mozilla/firefox 3.0.8
mozilla/firefox 3.0.9
... and 40 more
Published Dec 07, 2011
Tracked Since Feb 18, 2026