Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-1947
HistoryJun 06, 2012 - 12:00 a.m.

CVE-2012-1947

2012-06-0600:00:00
ubuntu.com
ubuntu.com
12

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.137

Percentile

95.6%

Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla
Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0
through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10
allows remote attackers to execute arbitrary code via vectors that trigger
a character-set conversion failure.

OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchfirefox< 13.0+build1-0ubuntu0.10.04.1UNKNOWN
ubuntu11.04noarchfirefox< 13.0+build1-0ubuntu0.11.04.1UNKNOWN
ubuntu11.10noarchfirefox< 13.0+build1-0ubuntu0.11.10.1UNKNOWN
ubuntu12.04noarchfirefox< 13.0+build1-0ubuntu0.12.04.1UNKNOWN
ubuntu10.04noarchthunderbird< 13.0.1+build1-0ubuntu0.10.04.1UNKNOWN
ubuntu11.04noarchthunderbird< 13.0.1+build1-0ubuntu0.11.04.1UNKNOWN
ubuntu11.10noarchthunderbird< 13.0.1+build1-0ubuntu0.11.10.1UNKNOWN
ubuntu12.04noarchthunderbird< 13.0.1+build1-0ubuntu0.12.04.1UNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.137

Percentile

95.6%