CVE-2012-1976
published 2012-08-29CVE-2012-1976: Use-after-free vulnerability in the nsHTMLSelectElement::SubmitNamesValues function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird…
PriorityP340critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.61%
92.0th percentile
Use-after-free vulnerability in the nsHTMLSelectElement::SubmitNamesValues function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| mozilla | firefox | < 15.0 | 15.0 |
| mozilla | firefox | >= 10.0 < 10.0.7 | 10.0.7 |
| mozilla | seamonkey | < 2.12 | 2.12 |
| mozilla | thunderbird | < 15.0 | 15.0 |
| mozilla | thunderbird_esr | >= 10.0 < 10.0.7 | 10.0.7 |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird regressions
vendor_ubuntu·2012-09-28·CVSS 4.3
[MEDIUM] Thunderbird regressions
Title: Thunderbird regressions
Summary: USN-1551-1 introduced regressions in Thunderbird.
USN-1551-1 fixed vulnerabilities in Thunderbird. The new package caused a
regression in the message editor and certain performance regressions as
well. This update fixes the problems.
Original advisory details:
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Thunderbird. If the user
were tricked into opening a specially crafted E-Mail, an attacker could
exploit these to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discove
Ubuntu
Firefox regression
vendor_ubuntu·2012-09-11·CVSS 4.3
[MEDIUM] Firefox regression
Title: Firefox regression
Summary: USN-1548-1 introduced a regression in Firefox.
USN-1548-1 fixed vulnerabilities in Firefox. The new package caused a
regression in Private Browsing which could leak sites visited to the
browser cache. This update fixes the problem.
Original advisory details:
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Firefox. If the user were
tricked into opening a specially crafted page, an attacker could exploit
these to cause a denial of service via application crash, or potentially
execute code with the privileges of the user invoking Firefox.
(CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discovered multiple use-
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2012-08-30·CVSS 4.3
CVE-2012-1970 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Multiple security issues were fixed in Thunderbird.
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Thunderbird. If the user
were tricked into opening a specially crafted E-Mail, an attacker could
exploit these to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discovered multiple use-after-free vulnerabilities. If the
user were tricked into opening a specially crafted E-Mail, an attacker
could exploit these to cause a denial of service via application crash, or
potential
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2012-08-29·CVSS 4.3
CVE-2012-1970 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Multiple security issues were fixed in Firefox.
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Firefox. If the user were
tricked into opening a specially crafted page, an attacker could exploit
these to cause a denial of service via application crash, or potentially
execute code with the privileges of the user invoking Firefox.
(CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discovered multiple use-after-free vulnerabilities. If the
user were tricked into opening a specially crafted page, an attacker could
exploit these to cause a denial of service via application crash, or
potentially execute code with
Red Hat
Mozilla: Multiple Use-after-free issues (MFSA 2012-58)
vendor_redhat·2012-08-28·CVSS 10.0
CVE-2012-1976 [CRITICAL] CWE-416 Mozilla: Multiple Use-after-free issues (MFSA 2012-58)
Mozilla: Multiple Use-after-free issues (MFSA 2012-58)
Use-after-free vulnerability in the nsHTMLSelectElement::SubmitNamesValues function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
GHSA
GHSA-27p7-3j3g-v9wc: Use-after-free vulnerability in the nsHTMLSelectElement::SubmitNamesValues function in Mozilla Firefox before 15
ghsa_unreviewed·2022-05-13
CVE-2012-1976 [HIGH] CWE-416 GHSA-27p7-3j3g-v9wc: Use-after-free vulnerability in the nsHTMLSelectElement::SubmitNamesValues function in Mozilla Firefox before 15
Use-after-free vulnerability in the nsHTMLSelectElement::SubmitNamesValues function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1210.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1211.htmlhttp://www.debian.org/security/2012/dsa-2553http://www.debian.org/security/2012/dsa-2554http://www.debian.org/security/2012/dsa-2556http://www.mozilla.org/security/announce/2012/mfsa2012-58.htmlhttp://www.securityfocus.com/bid/55319http://www.ubuntu.com/usn/USN-1548-1http://www.ubuntu.com/usn/USN-1548-2http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfhttps://bugzilla.mozilla.org/show_bug.cgi?id=776213https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16818http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1210.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1211.htmlhttp://www.debian.org/security/2012/dsa-2553http://www.debian.org/security/2012/dsa-2554http://www.debian.org/security/2012/dsa-2556http://www.mozilla.org/security/announce/2012/mfsa2012-58.htmlhttp://www.securityfocus.com/bid/55319http://www.ubuntu.com/usn/USN-1548-1http://www.ubuntu.com/usn/USN-1548-2http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfhttps://bugzilla.mozilla.org/show_bug.cgi?id=776213https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16818
2012-08-29
Published