Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly iterate through the characters in a text run, which allows remote attackers to execute arbitrary code via a crafted document.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
AV:N/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
| Mozilla |
|
| Redhat |
|
Configuration 1 [-]
|
Configuration 2 [-]
|
Configuration 3 [-]
|
Configuration 4 [-]
|
Configuration 5 [-]
|
| Package | CPE | Advisory | Released Date |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | |||
| firefox-0:10.0.7-1.el5_8 | cpe:/o:redhat:enterprise_linux:5 | RHSA-2012:1210 | 2012-08-29T00:00:00Z |
| xulrunner-0:10.0.7-2.el5_8 | cpe:/o:redhat:enterprise_linux:5 | RHSA-2012:1210 | 2012-08-29T00:00:00Z |
| thunderbird-0:10.0.7-1.el5_8 | cpe:/o:redhat:enterprise_linux:5 | RHSA-2012:1211 | 2012-08-29T00:00:00Z |
| Red Hat Enterprise Linux 6 | |||
| firefox-0:10.0.7-1.el6_3 | cpe:/o:redhat:enterprise_linux:6 | RHSA-2012:1210 | 2012-08-29T00:00:00Z |
| xulrunner-0:10.0.7-1.el6_3 | cpe:/o:redhat:enterprise_linux:6 | RHSA-2012:1210 | 2012-08-29T00:00:00Z |
| thunderbird-0:10.0.7-1.el6_3 | cpe:/o:redhat:enterprise_linux:6 | RHSA-2012:1211 | 2012-08-29T00:00:00Z |
References
History
Mon, 21 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mozilla:firefox_esr:10.0.2:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:10.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mozilla firefox Esr
|
Mon, 21 Oct 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mozilla:firefox_esr:10.0.4:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:10.0.5:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:10.0.6:*:*:*:*:*:*:* |
cpe:2.3:a:mozilla:firefox:10.0.3:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:10.0.4:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:10.0.5:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:10.0.6:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: mitre
Published: 2012-08-29T10:00:00
Updated: 2024-08-06T20:21:04.157Z
Reserved: 2012-07-11T00:00:00
Link: CVE-2012-3962
No data.
Status : Deferred
Published: 2012-08-29T10:56:40.537
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-3962
ReportizFlow