CVE-2012-0463

high
Published 2012-03-14 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 does not check the validity of an instance after event dispatching, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, as demonstrated by Mobile Firefox on Android.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://bugzilla.mozilla.org/show_bug.cgi?id=688208

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.mozilla.org/security/announce/2012/mfsa2012-19.html

Application impact

VendorProductVersionsFixed
mozilla mozillafirefox{"endIncluding":"3.6.27"}
mozilla mozillafirefox10.0
mozilla mozillafirefox10.0.1
mozilla mozillafirefox10.0.2
mozilla mozillathunderbird{"startIncluding":"1.0","endIncluding":"3.1.19"}
mozilla mozillathunderbird_esr10.0
mozilla mozillathunderbird_esr10.0.1
mozilla mozillathunderbird_esr10.0.2
mozilla mozillaseamonkey-
mozilla mozillaseamonkey1.0
mozilla mozillaseamonkey1.0.1
mozilla mozillaseamonkey1.0.2
mozilla mozillaseamonkey1.0.3
mozilla mozillaseamonkey1.0.4
mozilla mozillaseamonkey1.0.5
mozilla mozillaseamonkey1.0.6
mozilla mozillaseamonkey1.0.7
mozilla mozillaseamonkey1.0.8
mozilla mozillaseamonkey1.0.9
mozilla mozillaseamonkey1.1
mozilla mozillaseamonkey1.1.1
mozilla mozillaseamonkey1.1.2
mozilla mozillaseamonkey1.1.3
mozilla mozillaseamonkey1.1.4
mozilla mozillaseamonkey1.1.5
mozilla mozillaseamonkey1.1.6
mozilla mozillaseamonkey1.1.7
mozilla mozillaseamonkey1.1.8
mozilla mozillaseamonkey1.1.9
mozilla mozillaseamonkey1.1.10
mozilla mozillaseamonkey1.1.11
mozilla mozillaseamonkey1.1.12
mozilla mozillaseamonkey1.1.13
mozilla mozillaseamonkey1.1.14
mozilla mozillaseamonkey1.1.15
mozilla mozillaseamonkey1.1.16
mozilla mozillaseamonkey1.1.17
mozilla mozillaseamonkey1.1.18
mozilla mozillaseamonkey1.1.19
mozilla mozillaseamonkey1.5.0.8
mozilla mozillaseamonkey1.5.0.9
mozilla mozillaseamonkey1.5.0.10
mozilla mozillaseamonkey2.0
mozilla mozillaseamonkey2.0.1
mozilla mozillaseamonkey2.0.2
mozilla mozillaseamonkey2.0.3
mozilla mozillaseamonkey2.0.4
mozilla mozillaseamonkey2.0.5
mozilla mozillaseamonkey2.0.6
mozilla mozillaseamonkey2.0.7
mozilla mozillaseamonkey2.0.8
mozilla mozillaseamonkey2.0.9
mozilla mozillaseamonkey2.0.10
mozilla mozillaseamonkey2.0.11
mozilla mozillaseamonkey2.0.12
mozilla mozillaseamonkey2.0.13
mozilla mozillaseamonkey2.0.14
mozilla mozillaseamonkey2.1
mozilla mozillaseamonkey2.2
mozilla mozillaseamonkey2.3
mozilla mozillaseamonkey2.3.1
mozilla mozillaseamonkey2.3.2
mozilla mozillaseamonkey2.3.3
mozilla mozillaseamonkey2.4
mozilla mozillaseamonkey2.4.1
mozilla mozillaseamonkey2.5
mozilla mozillaseamonkey2.6
mozilla mozillaseamonkey2.6.1
mozilla mozillaseamonkey2.7
mozilla mozillaseamonkey2.7.1
mozilla mozillaseamonkey2.7.2

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.