CVE-2012-4190
published 2012-10-12CVE-2012-4190: The FT2FontEntry::CreateFontEntry function in FreeType, as used in the Android build of Mozilla Firefox before 16.0.1 on CyanogenMod 10, allows remote…
PriorityP335critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.20%
89.9th percentile
The FT2FontEntry::CreateFontEntry function in FreeType, as used in the Android build of Mozilla Firefox before 16.0.1 on CyanogenMod 10, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
Affected
153 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cyanogenmod | cyanogenmod | — | — |
| mozilla | firefox | <= 16.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vp62-hh5v-fxcw: The FT2FontEntry::CreateFontEntry function in FreeType, as used in the Android build of Mozilla Firefox before 16
ghsa_unreviewed·2022-05-17
CVE-2012-4190 [HIGH] CWE-119 GHSA-vp62-hh5v-fxcw: The FT2FontEntry::CreateFontEntry function in FreeType, as used in the Android build of Mozilla Firefox before 16
The FT2FontEntry::CreateFontEntry function in FreeType, as used in the Android build of Mozilla Firefox before 16.0.1 on CyanogenMod 10, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
Red Hat
freetype: memory corruption and application crash (reported against firefox on android)
vendor_redhat·2012-10-11·CVSS 10.0
CVE-2012-4190 [CRITICAL] freetype: memory corruption and application crash (reported against firefox on android)
freetype: memory corruption and application crash (reported against firefox on android)
The FT2FontEntry::CreateFontEntry function in FreeType, as used in the Android build of Mozilla Firefox before 16.0.1 on CyanogenMod 10, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
Statement: Not Vulnerable. This issue does not affect the version of freetype as shipped with Red Hat Enterprise Linux 5 and 6.
Package: freetype (Red Hat Enterprise Linux 5) - Not affected
Package: freetype (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
http://www.mozilla.org/security/announce/2012/mfsa2012-88.htmlhttp://www.securitytracker.com/id?1027653https://bugzilla.mozilla.org/show_bug.cgi?id=790139https://exchange.xforce.ibmcloud.com/vulnerabilities/79208http://www.mozilla.org/security/announce/2012/mfsa2012-88.htmlhttp://www.securitytracker.com/id?1027653https://bugzilla.mozilla.org/show_bug.cgi?id=790139https://exchange.xforce.ibmcloud.com/vulnerabilities/79208
2012-10-12
Published