Lucene search

K
cve[email protected]CVE-2012-0444
HistoryFeb 01, 2012 - 4:55 p.m.

CVE-2012-0444

2012-02-0116:55:01
CWE-119
web.nvd.nist.gov
144
cve-2012-0444
mozilla firefox
thunderbird
seamonkey
denial of service
memory corruption
application crash
arbitrary code execution
ogg vorbis.

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8.9 High

AI Score

Confidence

High

0.885 High

EPSS

Percentile

98.7%

Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.

Affected configurations

NVD
Node
mozillafirefoxRange<3.6.26
OR
mozillafirefoxRange4.010.0
OR
mozillaseamonkeyRange<2.7
OR
mozillathunderbirdRange<3.1.18
OR
mozillathunderbirdRange5.010.0
Node
debiandebian_linuxMatch5.0
OR
debiandebian_linuxMatch6.0
Node
opensuseopensuseMatch11.4
OR
suselinux_enterprise_desktopMatch10sp4
OR
suselinux_enterprise_desktopMatch11sp1
OR
suselinux_enterprise_serverMatch10sp4
OR
suselinux_enterprise_serverMatch11sp1
OR
suselinux_enterprise_serverMatch11sp1vmware
OR
suselinux_enterprise_software_development_kitMatch10sp4
OR
suselinux_enterprise_software_development_kitMatch11sp1
Node
canonicalubuntu_linuxMatch10.04-
OR
canonicalubuntu_linuxMatch10.10
OR
canonicalubuntu_linuxMatch11.04
OR
canonicalubuntu_linuxMatch11.10

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8.9 High

AI Score

Confidence

High

0.885 High

EPSS

Percentile

98.7%