CVE-2012-0472
The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9, when certain Windows Vista and Windows 7 configurations are…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.10%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9, when certain Windows Vista and Windows 7 configurations are used, does not properly restrict font-rendering attempts, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 4.10% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- mozilla/firefox · mozilla/thunderbird · mozilla/thunderbird esr · mozilla/seamonkey
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/48972Not Applicable, Permissions Required
- http://secunia.com/advisories/49055Not Applicable, Permissions Required
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:066
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:081
- http://www.mozilla.org/security/announce/2012/mfsa2012-25.htmlVendor Advisory
- http://www.securityfocus.com/bid/53218Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=744480Issue Tracking
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17067
- http://secunia.com/advisories/48972Not Applicable, Permissions Required
- http://secunia.com/advisories/49055Not Applicable, Permissions Required
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:066
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:081
- http://www.mozilla.org/security/announce/2012/mfsa2012-25.htmlVendor Advisory
- http://www.securityfocus.com/bid/53218Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=744480Issue Tracking
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17067
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.