CVE-2012-0469
published 2012-04-25CVE-2012-0469: Use-after-free vulnerability in the mozilla::dom::indexedDB::IDBKeyRange::cycleCollection::Trace function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x…
PriorityP348critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.37%
93.7th percentile
Use-after-free vulnerability in the mozilla::dom::indexedDB::IDBKeyRange::cycleCollection::Trace function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to execute arbitrary code via vectors related to crafted IndexedDB data.
Affected
103 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 2.9 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2012-05-04·CVSS 10.0
CVE-2011-1187 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
USN-1430-1 fixed vulnerabilities in Firefox. This update provides the
corresponding fixes for Thunderbird.
Original advisory details:
Bob Clary, Christian Holler, Brian Hackett, Bobby Holley, Gary Kwong,
Hilary Hall, Honza Bambas, Jesse Ruderman, Julian Seward, and Olli Pettay
discovered memory safety issues affecting Firefox. If the user were tricked
into opening a specially crafted page, an attacker could exploit these to
cause a denial of service via application crash, or potentially execute
code with the privileges of the user invoking Firefox. (CVE-2012-0467,
CVE-2012-0468)
Aki Helin discovered a use-after-free vulnerability in XPConnect. An
attacker could potentially exploit this to ex
Ubuntu
ubufox update
vendor_ubuntu·2012-04-27·CVSS 10.0
[CRITICAL] ubufox update
Title: ubufox update
Summary: This update provides compatible ubufox packages for the latest Firefox.
USN-1430-1 fixed vulnerabilities in Firefox. This update provides an
updated ubufox package for use with the latest Firefox.
Original advisory details:
Bob Clary, Christian Holler, Brian Hackett, Bobby Holley, Gary Kwong,
Hilary Hall, Honza Bambas, Jesse Ruderman, Julian Seward, and Olli Pettay
discovered memory safety issues affecting Firefox. If the user were tricked
into opening a specially crafted page, an attacker could exploit these to
cause a denial of service via application crash, or potentially execute
code with the privileges of the user invoking Firefox. (CVE-2012-0467,
CVE-2012-0468)
Aki Helin discovered a use-after-free vulnerability in XPConnect. An
attacker could poten
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2012-04-27·CVSS 10.0
CVE-2012-0467 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Bob Clary, Christian Holler, Brian Hackett, Bobby Holley, Gary Kwong,
Hilary Hall, Honza Bambas, Jesse Ruderman, Julian Seward, and Olli Pettay
discovered memory safety issues affecting Firefox. If the user were tricked
into opening a specially crafted page, an attacker could exploit these to
cause a denial of service via application crash, or potentially execute
code with the privileges of the user invoking Firefox. (CVE-2012-0467,
CVE-2012-0468)
Aki Helin discovered a use-after-free vulnerability in XPConnect. An
attacker could potentially exploit this to execute arbitrary code with the
privileges of the user invoking Firefox. (CVE-2012-0469)
Atte Kettunen discovered that invalid frees cause heap c
Red Hat
Mozilla: use-after-free in IDBKeyRange (MFSA 2012-22)
vendor_redhat·2012-04-24·CVSS 10.0
CVE-2012-0469 [CRITICAL] CWE-416 Mozilla: use-after-free in IDBKeyRange (MFSA 2012-22)
Mozilla: use-after-free in IDBKeyRange (MFSA 2012-22)
Use-after-free vulnerability in the mozilla::dom::indexedDB::IDBKeyRange::cycleCollection::Trace function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to execute arbitrary code via vectors related to crafted IndexedDB data.
GHSA
GHSA-86c5-mchr-88xj: Use-after-free vulnerability in the mozilla::dom::indexedDB::IDBKeyRange::cycleCollection::Trace function in Mozilla Firefox 4
ghsa_unreviewed·2022-05-04
CVE-2012-0469 [HIGH] GHSA-86c5-mchr-88xj: Use-after-free vulnerability in the mozilla::dom::indexedDB::IDBKeyRange::cycleCollection::Trace function in Mozilla Firefox 4
Use-after-free vulnerability in the mozilla::dom::indexedDB::IDBKeyRange::cycleCollection::Trace function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to execute arbitrary code via vectors related to crafted IndexedDB data.
No detection rules found.
arXiv
SeMalloc: Semantics-Informed Memory Allocator
arxiv_fulltext·2024-05-22
SeMalloc: Semantics-Informed Memory Allocator
: Semantics-Informed Memory Allocator
fancyplain
Rev.
\ of LastPage
Ruizhe Wang
[email protected]
University of Waterloo
Canada
Meng Xu
[email protected]
University of Waterloo
Canada
N. Asokan
[email protected]
University of Waterloo
Canada
CCSXML
10002978.10003022.10003023
Security and privacy Software security engineering
500
CCSXML
[500]Security and privacy Software security engineering
Static analysis, use-after-free, secure memory allocator
acmlicensed
2018
2018
XXXXXXX.XXXXXXX
[CCS '24]the 2024 ACM SIGSAC Conference on Computer and Communications
SecurityOctober 14--18,
2024Salt Lake City, UT
## Abstract
Use-after-free (UAF)
is a critical and prevalent problem
in memory unsafe languages.
While many solutions have been proposed,
balancing
security, run-ti
Bugzilla
CVE-2012-0469 Mozilla: use-after-free in IDBKeyRange (MFSA 2012-22)
bugzilla·2012-04-22·CVSS 10.0
CVE-2012-0469 [CRITICAL] CVE-2012-0469 Mozilla: use-after-free in IDBKeyRange (MFSA 2012-22)
CVE-2012-0469 Mozilla: use-after-free in IDBKeyRange (MFSA 2012-22)
Using the Address Sanitizer tool, security researcher Aki Helin from OUSPG found that IDBKeyRange of indexedDB remains in the XPConnect hashtable instead of being unlinked before being destroyed. When it is destroyed, this causes a use-after-free, which is potentially exploitable.
Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-22.html
Discussion:
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Aki Helin from OUSPG as the original reporter.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2012:0516 https://rhn.redhat.com/errata/RHSA-2012-0516.html
---
This iss
http://secunia.com/advisories/48972http://secunia.com/advisories/49047http://secunia.com/advisories/49055http://www.mandriva.com/security/advisories?name=MDVSA-2012:066http://www.mandriva.com/security/advisories?name=MDVSA-2012:081http://www.mozilla.org/security/announce/2012/mfsa2012-22.htmlhttp://www.securityfocus.com/bid/53220https://bugzilla.mozilla.org/show_bug.cgi?id=738985https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16734http://secunia.com/advisories/48972http://secunia.com/advisories/49047http://secunia.com/advisories/49055http://www.mandriva.com/security/advisories?name=MDVSA-2012:066http://www.mandriva.com/security/advisories?name=MDVSA-2012:081http://www.mozilla.org/security/announce/2012/mfsa2012-22.htmlhttp://www.securityfocus.com/bid/53220https://bugzilla.mozilla.org/show_bug.cgi?id=738985https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16734
2012-04-25
Published