CVE-2012-0444
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.94%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 7.94% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird · debian/debian linux · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00003.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00007.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00011.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/48043Third Party Advisory
- http://secunia.com/advisories/48095Third Party Advisory
- http://www.debian.org/security/2012/dsa-2400Third Party Advisory
- http://www.debian.org/security/2012/dsa-2402Third Party Advisory
- http://www.debian.org/security/2012/dsa-2406Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:013Third Party Advisory
- http://www.mozilla.org/security/announce/2012/mfsa2012-07.htmlVendor Advisory
- http://www.securityfocus.com/bid/51753Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1370-1Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=719612Exploit, Issue Tracking, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72858Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14464Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00003.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00007.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00011.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/48043Third Party Advisory
- http://secunia.com/advisories/48095Third Party Advisory
- http://www.debian.org/security/2012/dsa-2400Third Party Advisory
- http://www.debian.org/security/2012/dsa-2402Third Party Advisory
- http://www.debian.org/security/2012/dsa-2406Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:013Third Party Advisory
- http://www.mozilla.org/security/announce/2012/mfsa2012-07.htmlVendor Advisory
- http://www.securityfocus.com/bid/51753Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1370-1Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=719612Exploit, Issue Tracking, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72858Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14464Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.