CVE-2012-1971
published 2012-08-29CVE-2012-1971: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 allow remote…
PriorityP338critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.81%
88.9th percentile
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to garbage collection after certain MethodJIT execution, and unknown other vectors.
Affected
264 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 14.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird regressions
vendor_ubuntu·2012-09-28·CVSS 4.3
[MEDIUM] Thunderbird regressions
Title: Thunderbird regressions
Summary: USN-1551-1 introduced regressions in Thunderbird.
USN-1551-1 fixed vulnerabilities in Thunderbird. The new package caused a
regression in the message editor and certain performance regressions as
well. This update fixes the problems.
Original advisory details:
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Thunderbird. If the user
were tricked into opening a specially crafted E-Mail, an attacker could
exploit these to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discove
Ubuntu
Firefox regression
vendor_ubuntu·2012-09-11·CVSS 4.3
[MEDIUM] Firefox regression
Title: Firefox regression
Summary: USN-1548-1 introduced a regression in Firefox.
USN-1548-1 fixed vulnerabilities in Firefox. The new package caused a
regression in Private Browsing which could leak sites visited to the
browser cache. This update fixes the problem.
Original advisory details:
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Firefox. If the user were
tricked into opening a specially crafted page, an attacker could exploit
these to cause a denial of service via application crash, or potentially
execute code with the privileges of the user invoking Firefox.
(CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discovered multiple use-
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2012-08-30·CVSS 4.3
CVE-2012-1970 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Multiple security issues were fixed in Thunderbird.
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Thunderbird. If the user
were tricked into opening a specially crafted E-Mail, an attacker could
exploit these to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discovered multiple use-after-free vulnerabilities. If the
user were tricked into opening a specially crafted E-Mail, an attacker
could exploit these to cause a denial of service via application crash, or
potential
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2012-08-29·CVSS 4.3
CVE-2012-1970 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Multiple security issues were fixed in Firefox.
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Firefox. If the user were
tricked into opening a specially crafted page, an attacker could exploit
these to cause a denial of service via application crash, or potentially
execute code with the privileges of the user invoking Firefox.
(CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discovered multiple use-after-free vulnerabilities. If the
user were tricked into opening a specially crafted page, an attacker could
exploit these to cause a denial of service via application crash, or
potentially execute code with
Red Hat
Mozilla: Miscellaneous memory safety hazards (rv:15.0) (MFSA 2012-57)
vendor_redhat·2012-08-28·CVSS 9.3
CVE-2012-1971 [CRITICAL] Mozilla: Miscellaneous memory safety hazards (rv:15.0) (MFSA 2012-57)
Mozilla: Miscellaneous memory safety hazards (rv:15.0) (MFSA 2012-57)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to garbage collection after certain MethodJIT execution, and unknown other vectors.
Statement: Not Vulnerable. This issue does not affect the version of Firefox and Thunderbird package as shipped with Red Hat Enterprise Linux 5 and 6.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: th
GHSA
GHSA-g8hv-rq43-m54w: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15
ghsa_unreviewed·2022-05-17
CVE-2012-1971 [HIGH] GHSA-g8hv-rq43-m54w: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to garbage collection after certain MethodJIT execution, and unknown other vectors.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.htmlhttp://www.mozilla.org/security/announce/2012/mfsa2012-57.htmlhttp://www.ubuntu.com/usn/USN-1548-1http://www.ubuntu.com/usn/USN-1548-2http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfhttps://bugzilla.mozilla.org/show_bug.cgi?id=719750https://bugzilla.mozilla.org/show_bug.cgi?id=730208https://bugzilla.mozilla.org/show_bug.cgi?id=732870https://bugzilla.mozilla.org/show_bug.cgi?id=748119https://bugzilla.mozilla.org/show_bug.cgi?id=749039https://bugzilla.mozilla.org/show_bug.cgi?id=752038https://bugzilla.mozilla.org/show_bug.cgi?id=752087https://bugzilla.mozilla.org/show_bug.cgi?id=753162https://bugzilla.mozilla.org/show_bug.cgi?id=754150https://bugzilla.mozilla.org/show_bug.cgi?id=754242https://bugzilla.mozilla.org/show_bug.cgi?id=755916https://bugzilla.mozilla.org/show_bug.cgi?id=765936https://bugzilla.mozilla.org/show_bug.cgi?id=773097https://bugzilla.mozilla.org/show_bug.cgi?id=779849https://bugzilla.mozilla.org/show_bug.cgi?id=780712https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16841http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.htmlhttp://www.mozilla.org/security/announce/2012/mfsa2012-57.htmlhttp://www.ubuntu.com/usn/USN-1548-1http://www.ubuntu.com/usn/USN-1548-2http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfhttps://bugzilla.mozilla.org/show_bug.cgi?id=719750https://bugzilla.mozilla.org/show_bug.cgi?id=730208https://bugzilla.mozilla.org/show_bug.cgi?id=732870https://bugzilla.mozilla.org/show_bug.cgi?id=748119https://bugzilla.mozilla.org/show_bug.cgi?id=749039https://bugzilla.mozilla.org/show_bug.cgi?id=752038https://bugzilla.mozilla.org/show_bug.cgi?id=752087https://bugzilla.mozilla.org/show_bug.cgi?id=753162https://bugzilla.mozilla.org/show_bug.cgi?id=754150https://bugzilla.mozilla.org/show_bug.cgi?id=754242https://bugzilla.mozilla.org/show_bug.cgi?id=755916https://bugzilla.mozilla.org/show_bug.cgi?id=765936https://bugzilla.mozilla.org/show_bug.cgi?id=773097https://bugzilla.mozilla.org/show_bug.cgi?id=779849https://bugzilla.mozilla.org/show_bug.cgi?id=780712https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16841
2012-08-29
Published