CVE-2002-2437

The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.

Scoring

CVSS base score
0.01
EPSS probability
0.29%
Published
2011-12-07
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs