CVE-2012-0463
published 2012-03-14CVE-2012-0463: The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.04%
89.5th percentile
The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 does not check the validity of an instance after event dispatching, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, as demonstrated by Mobile Firefox on Android.
Affected
72 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.6.27 | — |
| mozilla | firefox | <= 10.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-updates/2012-03/msg00042.htmlhttp://secunia.com/advisories/48402http://secunia.com/advisories/48553http://secunia.com/advisories/48561http://secunia.com/advisories/48624http://secunia.com/advisories/48629http://www.mozilla.org/security/announce/2012/mfsa2012-19.htmlhttp://www.securityfocus.com/bid/52466http://www.securitytracker.com/id?1026801http://www.securitytracker.com/id?1026803http://www.securitytracker.com/id?1026804https://bugzilla.mozilla.org/show_bug.cgi?id=688208https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15143http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-updates/2012-03/msg00042.htmlhttp://secunia.com/advisories/48402http://secunia.com/advisories/48553http://secunia.com/advisories/48561http://secunia.com/advisories/48624http://secunia.com/advisories/48629http://www.mozilla.org/security/announce/2012/mfsa2012-19.htmlhttp://www.securityfocus.com/bid/52466http://www.securitytracker.com/id?1026801http://www.securitytracker.com/id?1026803http://www.securitytracker.com/id?1026804https://bugzilla.mozilla.org/show_bug.cgi?id=688208https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15143
2012-03-14
Published