CVE-2012-0467
critical
CVSS v3
—
CVSS v2
10.0
VIR risk
10.0
Description
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://www.mozilla.org/security/announce/2012/mfsa2012-20.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| mozilla | firefox | 4.0 | |
| mozilla | firefox | 4.0.1 | |
| mozilla | firefox | 5.0 | |
| mozilla | firefox | 5.0.1 | |
| mozilla | firefox | 6.0 | |
| mozilla | firefox | 6.0.1 | |
| mozilla | firefox | 6.0.2 | |
| mozilla | firefox | 7.0 | |
| mozilla | firefox | 7.0.1 | |
| mozilla | firefox | 8.0 | |
| mozilla | firefox | 8.0.1 | |
| mozilla | firefox | 9.0 | |
| mozilla | firefox | 9.0.1 | |
| mozilla | firefox | 10.0 | |
| mozilla | firefox | 10.0.1 | |
| mozilla | firefox | 10.0.2 | |
| mozilla | firefox | 11.0 | |
| mozilla | firefox | 10.0.3 | |
| mozilla | thunderbird | 5.0 | |
| mozilla | thunderbird | 6.0 | |
| mozilla | thunderbird | 6.0.1 | |
| mozilla | thunderbird | 6.0.2 | |
| mozilla | thunderbird | 7.0 | |
| mozilla | thunderbird | 7.0.1 | |
| mozilla | thunderbird | 8.0 | |
| mozilla | thunderbird | 9.0 | |
| mozilla | thunderbird | 9.0.1 | |
| mozilla | thunderbird | 10.0 | |
| mozilla | thunderbird | 10.0.1 | |
| mozilla | thunderbird | 10.0.2 | |
| mozilla | thunderbird | 10.0.3 | |
| mozilla | thunderbird | 10.0.4 | |
| mozilla | thunderbird | 11.0 | |
| mozilla | thunderbird_esr | 10.0 | |
| mozilla | thunderbird_esr | 10.0.1 | |
| mozilla | thunderbird_esr | 10.0.2 | |
| mozilla | thunderbird_esr | 10.0.3 | |
| mozilla | seamonkey | {"endIncluding":"2.9"} | |
| mozilla | seamonkey | 1.0 | |
| mozilla | seamonkey | 1.0.1 | |
| mozilla | seamonkey | 1.0.2 | |
| mozilla | seamonkey | 1.0.3 | |
| mozilla | seamonkey | 1.0.4 | |
| mozilla | seamonkey | 1.0.5 | |
| mozilla | seamonkey | 1.0.6 | |
| mozilla | seamonkey | 1.0.7 | |
| mozilla | seamonkey | 1.0.8 | |
| mozilla | seamonkey | 1.0.9 | |
| mozilla | seamonkey | 1.1 | |
| mozilla | seamonkey | 1.1.1 | |
| mozilla | seamonkey | 1.1.2 | |
| mozilla | seamonkey | 1.1.3 | |
| mozilla | seamonkey | 1.1.4 | |
| mozilla | seamonkey | 1.1.5 | |
| mozilla | seamonkey | 1.1.6 | |
| mozilla | seamonkey | 1.1.7 | |
| mozilla | seamonkey | 1.1.8 | |
| mozilla | seamonkey | 1.1.9 | |
| mozilla | seamonkey | 1.1.10 | |
| mozilla | seamonkey | 1.1.11 | |
| mozilla | seamonkey | 1.1.12 | |
| mozilla | seamonkey | 1.1.13 | |
| mozilla | seamonkey | 1.1.14 | |
| mozilla | seamonkey | 1.1.15 | |
| mozilla | seamonkey | 1.1.16 | |
| mozilla | seamonkey | 1.1.17 | |
| mozilla | seamonkey | 1.1.18 | |
| mozilla | seamonkey | 1.1.19 | |
| mozilla | seamonkey | 1.5.0.8 | |
| mozilla | seamonkey | 1.5.0.9 | |
| mozilla | seamonkey | 1.5.0.10 | |
| mozilla | seamonkey | 2.0 | |
| mozilla | seamonkey | 2.0.1 | |
| mozilla | seamonkey | 2.0.2 | |
| mozilla | seamonkey | 2.0.3 | |
| mozilla | seamonkey | 2.0.4 | |
| mozilla | seamonkey | 2.0.5 | |
| mozilla | seamonkey | 2.0.6 | |
| mozilla | seamonkey | 2.0.7 | |
| mozilla | seamonkey | 2.0.8 | |
| mozilla | seamonkey | 2.0.9 | |
| mozilla | seamonkey | 2.0.10 | |
| mozilla | seamonkey | 2.0.11 | |
| mozilla | seamonkey | 2.0.12 | |
| mozilla | seamonkey | 2.0.13 | |
| mozilla | seamonkey | 2.0.14 | |
| mozilla | seamonkey | 2.1 | |
| mozilla | seamonkey | 2.2 | |
| mozilla | seamonkey | 2.3 | |
| mozilla | seamonkey | 2.3.1 | |
| mozilla | seamonkey | 2.3.2 | |
| mozilla | seamonkey | 2.3.3 | |
| mozilla | seamonkey | 2.4 | |
| mozilla | seamonkey | 2.4.1 | |
| mozilla | seamonkey | 2.5 | |
| mozilla | seamonkey | 2.6 | |
| mozilla | seamonkey | 2.6.1 | |
| mozilla | seamonkey | 2.7 | |
| mozilla | seamonkey | 2.7.1 | |
| mozilla | seamonkey | 2.7.2 | |
| mozilla | seamonkey | 2.8 | |
| mozilla | seamonkey | 2.9 | |
References
- http://secunia.com/advisories/48920
- http://secunia.com/advisories/48922
- http://secunia.com/advisories/48972
- http://secunia.com/advisories/49047
- http://secunia.com/advisories/49055
- http://www.debian.org/security/2012/dsa-2457
- http://www.debian.org/security/2012/dsa-2458
- http://www.debian.org/security/2012/dsa-2464
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:066
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:081
- http://www.mozilla.org/security/announce/2012/mfsa2012-20.html
- http://www.securityfocus.com/bid/53223
- https://bugzilla.mozilla.org/show_bug.cgi?id=680456
- https://bugzilla.mozilla.org/show_bug.cgi?id=706381
- https://bugzilla.mozilla.org/show_bug.cgi?id=708825
- https://bugzilla.mozilla.org/show_bug.cgi?id=714614
- https://bugzilla.mozilla.org/show_bug.cgi?id=716556
- https://bugzilla.mozilla.org/show_bug.cgi?id=720305
- https://bugzilla.mozilla.org/show_bug.cgi?id=723453
- https://bugzilla.mozilla.org/show_bug.cgi?id=726332
- https://bugzilla.mozilla.org/show_bug.cgi?id=726502
- https://bugzilla.mozilla.org/show_bug.cgi?id=732941
- https://bugzilla.mozilla.org/show_bug.cgi?id=732951
- https://bugzilla.mozilla.org/show_bug.cgi?id=733282
- https://bugzilla.mozilla.org/show_bug.cgi?id=733979
Verify integrity in audit chain (admin only). AS-IS.