CVE-2012-1947
published 2012-06-05CVE-2012-1947: Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through…
PriorityP347critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.67%
90.7th percentile
Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.
Affected
106 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 2.9 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_ubuntu10.0CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2012-06-27·CVSS 10.0
CVE-2011-3101 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
USN-1463-1 fixed vulnerabilities in Firefox. This update provides the
corresponding fixes for Thunderbird.
Original advisory details:
Jesse Ruderman, Igor Bukanov, Bill McCloskey, Christian Holler, Andrew
McCreight, Olli Pettay, Boris Zbarsky, and Brian Bondy discovered memory
safety issues affecting Firefox. If the user were tricked into opening a
specially crafted page, an attacker could possibly exploit these to cause a
denial of service via application crash, or potentially execute code with
the privileges of the user invoking Firefox. (CVE-2012-1937, CVE-2012-1938)
It was discovered that Mozilla's WebGL implementation exposed a bug in
certain NVIDIA graphics drivers. The impact of this
Ubuntu
Firefox regressions
vendor_ubuntu·2012-06-20·CVSS 10.0
[CRITICAL] Firefox regressions
Title: Firefox regressions
Summary: USN-1463-1 introduced regressions in Firefox.
USN-1463-1 fixed vulnerabilities in Firefox. The new package caused a
regression in the rendering of Hebrew text and the ability of the Hotmail
inbox to auto-update. This update fixes the problem.
Original advisory details:
Jesse Ruderman, Igor Bukanov, Bill McCloskey, Christian Holler, Andrew
McCreight, Olli Pettay, Boris Zbarsky, and Brian Bondy discovered memory
safety issues affecting Firefox. If the user were tricked into opening a
specially crafted page, an attacker could possibly exploit these to cause a
denial of service via application crash, or potentially execute code with
the privileges of the user invoking Firefox. (CVE-2012-1937, CVE-2012-1938)
It was discovered that Mozilla's WebGL impleme
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2012-06-06·CVSS 10.0
CVE-2012-1937 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Jesse Ruderman, Igor Bukanov, Bill McCloskey, Christian Holler, Andrew
McCreight, Olli Pettay, Boris Zbarsky, and Brian Bondy discovered memory
safety issues affecting Firefox. If the user were tricked into opening a
specially crafted page, an attacker could possibly exploit these to cause a
denial of service via application crash, or potentially execute code with
the privileges of the user invoking Firefox. (CVE-2012-1937, CVE-2012-1938)
It was discovered that Mozilla's WebGL implementation exposed a bug in
certain NVIDIA graphics drivers. The impact of this issue has not been
disclosed at this time. (CVE-2011-3101)
Adam Barth discovered that certain inline event handlers were not being
blocked prop
Red Hat
Mozilla: Buffer overflow and use-after-free issues found using Address Sanitizer (MFSA 2012-40)
vendor_redhat·2012-06-05·CVSS 9.3
CVE-2012-1947 [CRITICAL] CWE-416 Mozilla: Buffer overflow and use-after-free issues found using Address Sanitizer (MFSA 2012-40)
Mozilla: Buffer overflow and use-after-free issues found using Address Sanitizer (MFSA 2012-40)
Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.
GHSA
GHSA-22c8-wr9r-qr3j: Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4
ghsa_unreviewed·2022-05-14
CVE-2012-1947 [HIGH] CWE-119 GHSA-22c8-wr9r-qr3j: Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4
Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.
No detection rules found.
No public exploits indexed.
arXiv
A Systematically Empirical Evaluation of Vulnerability Discovery Models: a Study on Browsers' Vulnerabilities
arxiv_fulltext·2013-06-11
A Systematically Empirical Evaluation of Vulnerability Discovery Models: a Study on Browsers' Vulnerabilities
A Systematically Empirical Evaluation of Vulnerability Discovery Models: a Study on Browsers' Vulnerabilities
Viet Hung Nguyen and Fabio Massacci
## Abstract
A precise vulnerability discovery model (VDM) will provide a useful insight to
assess software security, and could be a good prediction instrument for both
software vendors and users to understand security trends and plan ahead
patching schedule accordingly. Thus far, several models have been proposed and
validated. Yet, no systematically independent validation by somebody other than
the author exists. Furthermore, there are a number of issues that might bias
previous studies in the field. In this work, we fill in the gap by introducing
an empirical methodology that systematically evaluates the performance of a VDM
in two aspects: q
Bugzilla
CVE-2012-1940 CVE-2012-1941 CVE-2012-1947 Mozilla: Buffer overflow and use-after-free issues found using Address Sanitizer (MFSA 2012-40)
bugzilla·2012-06-03·CVSS 9.3
CVE-2012-1940 [CRITICAL] CVE-2012-1940 CVE-2012-1941 CVE-2012-1947 Mozilla: Buffer overflow and use-after-free issues found using Address Sanitizer (MFSA 2012-40)
CVE-2012-1940 CVE-2012-1941 CVE-2012-1947 Mozilla: Buffer overflow and use-after-free issues found using Address Sanitizer (MFSA 2012-40)
Security researcher Abhishek Arya of Google used the Address Sanitizer tool to uncover several issues: two heap buffer overflow bugs and a use-after-free problem. The first heap buffer overflow was found in conversion from unicode to native character sets when the function fails. The use-after-free occurs in nsFrameList when working with column layout with absolute positioning in a container that changes size. The second buffer overflow occurs in nsHTMLReflowState when a window is resized on a page with nested columns and a combination of absolute and relative positioning. All three of these issues are potentially exploitable.
Reference:
http://www.moz
http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-06/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0710.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0715.htmlhttp://www.debian.org/security/2012/dsa-2488http://www.debian.org/security/2012/dsa-2489http://www.mandriva.com/security/advisories?name=MDVSA-2012:088http://www.mozilla.org/security/announce/2012/mfsa2012-40.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=744541https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16911http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-06/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0710.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0715.htmlhttp://www.debian.org/security/2012/dsa-2488http://www.debian.org/security/2012/dsa-2489http://www.mandriva.com/security/advisories?name=MDVSA-2012:088http://www.mozilla.org/security/announce/2012/mfsa2012-40.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=744541https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16911
2012-06-05
Published