CVE-2012-0452

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger failure of an nsXBLDocumentInfo::ReadPrototypeBindings function call, related to the cycle collector's access to a hash table containing a stale XBL binding.
Severity
UNKNOWN
AV:N/AC:L/Au:N/C:P/I:P/A:P
Atk. Vector
NETWORK
Atk. Complexity
LOW
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
mozillafirefox
10.0
mozillathunderbird
10.0
mozillaseamonkey
2.7
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
precise
Fixed 11.0~b2+build1-0ubuntu1
released
oneiric
Fixed 10.0.1+build1-0ubuntu0.11.10.1
released
natty
Fixed 10.0.1+build1-0ubuntu0.11.04.1
released
maverick
Fixed 10.0.1+build1-0ubuntu0.10.10.1
released
lucid
Fixed 10.0.1+build1-0ubuntu0.10.04.1
released
hardy
ignored
seamonkey
precise
dne
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
hardy
ignored
thunderbird
precise
Fixed 12.0.1+build1-0ubuntu0.12.04.1
released
oneiric
Fixed 10.0.1+build1-0ubuntu0.11.10.1
released
natty
not-affected
maverick
not-affected
lucid
not-affected
hardy
ignored
xulrunner-1.9.2
precise
dne
oneiric
dne
natty
not-affected
maverick
not-affected
lucid
not-affected
hardy
ignored
xulrunner-2.0
precise
dne
oneiric
dne
natty
ignored
maverick
dne
lucid
dne
hardy
dne
Common Weakness Enumeration