Lucene search

K
cve[email protected]CVE-2012-3995
HistoryOct 10, 2012 - 5:55 p.m.

CVE-2012-3995

2012-10-1017:55:02
CWE-125
web.nvd.nist.gov
42
mozilla
firefox
thunderbird
cve-2012-3995
security
vulnerability
remote code execution
denial of service

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

9.4 High

AI Score

Confidence

High

0.023 Low

EPSS

Percentile

89.6%

The IsCSSWordSpacingSpace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.

Affected configurations

NVD
Node
mozillafirefox_esrRange<10.0.8
Node
mozillathunderbird_esrRange<10.0.8
Node
mozillafirefoxRange<16.0
Node
mozillathunderbirdRange<16.0
Node
mozillaseamonkeyRange<2.13
Node
canonicalubuntu_linuxMatch10.04-
OR
canonicalubuntu_linuxMatch11.04
OR
canonicalubuntu_linuxMatch11.10
OR
canonicalubuntu_linuxMatch12.04esm
OR
redhatenterprise_linux_desktopMatch5.0
OR
redhatenterprise_linux_desktopMatch6.0
OR
redhatenterprise_linux_eusMatch6.3
OR
redhatenterprise_linux_serverMatch5.0
OR
redhatenterprise_linux_serverMatch6.0
OR
redhatenterprise_linux_workstationMatch5.0
OR
redhatenterprise_linux_workstationMatch6.0
Node
suselinux_enterprise_desktopMatch10sp4
OR
suselinux_enterprise_desktopMatch11sp3
OR
suselinux_enterprise_sdkMatch10sp4
OR
suselinux_enterprise_serverMatch10sp4
OR
suselinux_enterprise_serverMatch11sp3
OR
suselinux_enterprise_serverMatch11sp3vmware

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

9.4 High

AI Score

Confidence

High

0.023 Low

EPSS

Percentile

89.6%