Loading...
Loading...
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly perform a cast of an unspecified variable during use of the instanceof operator on a JavaScript object, which allows remote attackers to execute arbitrary code or cause a denial of service (assertion failure) via a crafted web site.
October 10, 2012
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2012-3989
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.