CVE-2012-4212Use After Free in Mozilla Firefox

Severity
10.0CRITICALNVD
EPSS
1.5%
top 18.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 21
Latest updateMay 13

Description

Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages7 packages

NVDmozilla/firefox< 17.0
NVDmozilla/seamonkey< 2.14
NVDopensuse/opensuse11.4, 12.1, 12.2+2

Also affects: Ubuntu Linux 10.04, 11.10, 12.04, 12.10

🔴Vulnerability Details

2
GHSA
GHSA-qmfg-55x3-jqv9: Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 172022-05-13
CVEList
CVE-2012-4212: Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 172012-11-21

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2012-11-21
Ubuntu
Thunderbird vulnerabilities2012-11-21
Red Hat
Mozilla: Use-after-free and buffer overflow issues found using Address Sanitizer (MFSA 2012-105)2012-11-20

💬Community

1
Bugzilla
CVE-2012-4212 CVE-2012-4213 CVE-2012-4217 CVE-2012-4218 Mozilla: Use-after-free and buffer overflow issues found using Address Sanitizer (MFSA 2012-105)2012-11-19
CVE-2012-4212 — Use After Free in Mozilla Firefox | cvebase