Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-3972
HistoryAug 29, 2012 - 12:00 a.m.

CVE-2012-3972

2012-08-2900:00:00
ubuntu.com
ubuntu.com
17

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

0.002 Low

EPSS

Percentile

64.7%

The format-number functionality in the XSLT implementation in Mozilla
Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before
15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows
remote attackers to obtain sensitive information via unspecified vectors
that trigger a heap-based buffer over-read.

OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchfirefox< 15.0+build1-0ubuntu0.10.04.1UNKNOWN
ubuntu11.04noarchfirefox< 15.0+build1-0ubuntu0.11.04.2UNKNOWN
ubuntu11.10noarchfirefox< 15.0+build1-0ubuntu0.11.10.1UNKNOWN
ubuntu12.04noarchfirefox< 15.0+build1-0ubuntu0.12.04.1UNKNOWN
ubuntu12.10noarchfirefox< 15.0+build1-0ubuntu1UNKNOWN
ubuntu13.04noarchfirefox< 15.0+build1-0ubuntu1UNKNOWN
ubuntu13.10noarchfirefox< 15.0+build1-0ubuntu1UNKNOWN
ubuntu10.04noarchthunderbird< 15.0+build1-0ubuntu0.10.04.1UNKNOWN
ubuntu11.04noarchthunderbird< 15.0+build1-0ubuntu0.11.04.1UNKNOWN
ubuntu11.10noarchthunderbird< 15.0+build1-0ubuntu0.11.10.1UNKNOWN
Rows per page:
1-10 of 141

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

0.002 Low

EPSS

Percentile

64.7%