CVE-2012-4217Use After Free in Mozilla Firefox

Severity
9.3CRITICALNVD
EPSS
2.1%
top 15.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 21
Latest updateMay 13

Description

Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages8 packages

NVDmozilla/firefox< 17.0
NVDmozilla/seamonkey< 2.14
NVDopensuse/opensuse11.4, 12.1, 12.2+2

Also affects: Ubuntu Linux 10.04, 11.10, 12.04, 12.10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g65v-phv8-6928: Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox before 172022-05-13
CVEList
CVE-2012-4217: Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox before 172012-11-21

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2012-11-21
Ubuntu
Thunderbird vulnerabilities2012-11-21
Red Hat
Mozilla: Use-after-free and buffer overflow issues found using Address Sanitizer (MFSA 2012-105)2012-11-20

💬Community

1
Bugzilla
CVE-2012-4212 CVE-2012-4213 CVE-2012-4217 CVE-2012-4218 Mozilla: Use-after-free and buffer overflow issues found using Address Sanitizer (MFSA 2012-105)2012-11-19
CVE-2012-4217 — Use After Free in Mozilla Firefox | cvebase