Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.
lists.opensuse.org/opensuse-security-announce/2012-02/msg00003.html
lists.opensuse.org/opensuse-security-announce/2012-02/msg00007.html
lists.opensuse.org/opensuse-security-announce/2012-02/msg00011.html
secunia.com/advisories/48043
secunia.com/advisories/48095
www.debian.org/security/2012/dsa-2400
www.debian.org/security/2012/dsa-2402
www.debian.org/security/2012/dsa-2406
www.mandriva.com/security/advisories?name=MDVSA-2012:013
www.mozilla.org/security/announce/2012/mfsa2012-07.html
www.securityfocus.com/bid/51753
www.ubuntu.com/usn/USN-1370-1
bugzilla.mozilla.org/show_bug.cgi?id=719612
exchange.xforce.ibmcloud.com/vulnerabilities/72858
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14464