• Tenable
  • CVEs
  • Settings
    Links
    Tenable.io Tenable Community & Support Tenable University
    Severity
    Theme
  • Tenable
  • Links
  • Tenable.io
  • Tenable Community & Support
  • Tenable University
  • Settings
  • Severity
  • Theme
  • Newest
  • Updated
  • Search
  • Newest
  • Updated
  • Search
  1. CVEs
  2. CVE-2012-3962
  1. CVEs

CVE-2012-3962

high
  • Information
  • CPEs
  • Plugins

Description

Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly iterate through the characters in a text run, which allows remote attackers to execute arbitrary code via a crafted document.

References

http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00028.html

http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.html

http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.html

http://rhn.redhat.com/errata/RHSA-2012-1210.html

http://rhn.redhat.com/errata/RHSA-2012-1211.html

http://www.debian.org/security/2012/dsa-2553

http://www.debian.org/security/2012/dsa-2554

http://www.debian.org/security/2012/dsa-2556

http://www.mozilla.org/security/announce/2012/mfsa2012-58.html

http://www.ubuntu.com/usn/USN-1548-1

http://www.ubuntu.com/usn/USN-1548-2

http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf

https://bugzilla.mozilla.org/show_bug.cgi?id=769120

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16494

Details

Source: MITRE

Published: 2012-08-29

Updated: 2017-09-19

Type: NVD-CWE-Other

Risk Information

CVSS v2

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2023 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance