CVE-2012-3971Improper Restriction of Operations within the Bounds of a Memory Buffer in Mozilla Firefox

Severity
10.0CRITICALNVD
EPSS
3.1%
top 13.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 29
Latest updateMay 17

Description

Summer Institute of Linguistics (SIL) Graphite 2, as used in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the (1) Silf::readClassMap and (2) Pass::readPass functions.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

NVDmozilla/firefox14.0+130
NVDmozilla/seamonkey2.11+32
NVDmozilla/thunderbird14.0+99

🔴Vulnerability Details

2
GHSA
GHSA-88cw-97jp-xpvg: Summer Institute of Linguistics (SIL) Graphite 2, as used in Mozilla Firefox before 152022-05-17
CVEList
CVE-2012-3971: Summer Institute of Linguistics (SIL) Graphite 2, as used in Mozilla Firefox before 152012-08-29

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2012-08-30
Ubuntu
Firefox vulnerabilities2012-08-29
Red Hat
Mozilla: Graphite 2 memory corruption (MFSA 2012-64)2012-08-28

💬Community

1
Bugzilla
CVE-2012-3971 Mozilla: Graphite 2 memory corruption (MFSA 2012-64)2012-08-27
CVE-2012-3971 — Mozilla Firefox vulnerability | cvebase