CVE-2012-3105
The glBufferData function in the WebGL implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not properly mitigate an…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The glBufferData function in the WebGL implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not properly mitigate an unspecified flaw in an NVIDIA driver, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a related issue to CVE-2011-3101.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 3.66% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird · mozilla/thunderbird esr
- Source
- cve@mitre.org
References
- http://www.mozilla.org/security/announce/2012/mfsa2012-34.htmlVendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=744888
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16912
- http://www.mozilla.org/security/announce/2012/mfsa2012-34.htmlVendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=744888
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16912
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.