CVE-2012-3989: Mozilla: Crash with invalid cast when using instanceof operator (MFSA 2012-80)

Severity: Critical

CVSS Score: 9.3

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly perform a cast of an unspecified variable during use of the instanceof operator on a JavaScript object, which allows remote attackers to execute arbitrary code or cause a denial of service (assertion failure) via a crafted web site.