Lucene search

K
prionPRIOn knowledge basePRION:CVE-2012-3966
HistoryAug 29, 2012 - 10:56 a.m.

Memory corruption

2012-08-2910:56:00
PRIOn knowledge base
www.prio-n.com
6

8.1 High

AI Score

Confidence

High

0.117 Low

EPSS

Percentile

95.3%

Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a negative height value in a BMP image within a .ICO file, related to (1) improper handling of the transparency bitmask by the nsICODecoder component and (2) improper processing of the alpha channel by the nsBMPDecoder component.