CVE-2012-4186

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.

References

http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.html

http://osvdb.org/86117

http://rhn.redhat.com/errata/RHSA-2012-1351.html

http://secunia.com/advisories/50856

http://secunia.com/advisories/50892

http://secunia.com/advisories/50904

http://secunia.com/advisories/50935

http://secunia.com/advisories/50936

http://secunia.com/advisories/50984

http://secunia.com/advisories/51181

http://secunia.com/advisories/55318

http://www.debian.org/security/2012/dsa-2565

http://www.debian.org/security/2012/dsa-2569

http://www.debian.org/security/2012/dsa-2572

http://www.mandriva.com/security/advisories?name=MDVSA-2012:163

http://www.mozilla.org/security/announce/2012/mfsa2012-86.html

http://www.ubuntu.com/usn/USN-1611-1

https://bugzilla.mozilla.org/show_bug.cgi?id=785967

https://exchange.xforce.ibmcloud.com/vulnerabilities/79163

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16193

Details

Source: MITRE

Published: 2012-10-10

Updated: 2020-08-11

Type: CWE-119

Risk Information

CVSS v2

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

Tenable Plugins

View all (34 total)

IDNameProductFamilySeverity
83562SUSE SLED10 / SLED11 / SLES10 / SLES11 Security Update : Mozilla Firefox (SUSE-SU-2012:1351-1)NessusSuSE Local Security Checks
critical
74779openSUSE Security Update : MozillaFirefox (openSUSE-SU-2012:1345-1)NessusSuSE Local Security Checks
critical
68636Oracle Linux 6 : thunderbird (ELSA-2012-1351)NessusOracle Linux Local Security Checks
high
68635Oracle Linux 5 / 6 : firefox (ELSA-2012-1350)NessusOracle Linux Local Security Checks
high
64133SuSE 11.2 Security Update : Mozilla Firefox (SAT Patch Number 6951)NessusSuSE Local Security Checks
critical
63402GLSA-201301-01 : Mozilla Products: Multiple vulnerabilities (BEAST)NessusGentoo Local Security Checks
critical
62805Debian DSA-2572-1 : iceape - several vulnerabilitiesNessusDebian Local Security Checks
critical
62748Debian DSA-2569-1 : icedove - several vulnerabilitiesNessusDebian Local Security Checks
critical
62667Debian DSA-2565-1 : iceweasel - several vulnerabilitiesNessusDebian Local Security Checks
critical
62583SeaMonkey < 2.13 Multiple VulnerabilitiesNessusWindows
critical
62582Mozilla Thunderbird < 16.0 Multiple VulnerabilitiesNessusWindows
critical
62581Mozilla Thunderbird 10.0.x < 10.0.8 Multiple VulnerabilitiesNessusWindows
critical
62580Firefox < 16.0 Multiple VulnerabilitiesNessusWindows
critical
62579Firefox 10.0.x < 10.0.8 Multiple VulnerabilitiesNessusWindows
critical
62578Mozilla Thunderbird < 16.0 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
62577Mozilla Thunderbird 10.0.x < 10.0.8 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
62576Firefox < 16.0 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
62575Firefox < 10.0.8 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
62573SuSE 10 Security Update : Mozilla Firefox (ZYPP Patch Number 8327)NessusSuSE Local Security Checks
critical
801325Mozilla Firefox 15.x <= 15 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801323Mozilla Thunderbird 15.x <= 15 Multiple VulnerabilitiesLog Correlation EngineSMTP Clients
high
801301Mozilla SeaMonkey 2.x < 2.13 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
6604Mozilla Thunderbird < 16.0.1 Multiple VulnerabilitiesNessus Network MonitorSMTP Clients
high
6603SeaMonkey 2.x < 2.13 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
6602Mozilla Firefox < 16.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
62548Ubuntu 10.04 LTS / 11.04 / 11.10 / 12.04 LTS : thunderbird vulnerabilities (USN-1611-1)NessusUbuntu Local Security Checks
critical
62493Scientific Linux Security Update : thunderbird on SL5.x, SL6.x i386/x86_64 (20121009)NessusScientific Linux Local Security Checks
critical
62492Scientific Linux Security Update : firefox on SL5.x, SL6.x i386/x86_64 (20121009)NessusScientific Linux Local Security Checks
critical
62490FreeBSD : mozilla -- multiple vulnerabilities (6e5a9afd-12d3-11e2-b47d-c8600054b392)NessusFreeBSD Local Security Checks
critical
62485CentOS 5 / 6 : thunderbird (CESA-2012:1351)NessusCentOS Local Security Checks
high
62484CentOS 5 / 6 : firefox (CESA-2012:1350)NessusCentOS Local Security Checks
high
62476Ubuntu 10.04 LTS / 11.04 / 11.10 / 12.04 LTS : firefox vulnerabilities (USN-1600-1)NessusUbuntu Local Security Checks
critical
62473RHEL 5 / 6 : thunderbird (RHSA-2012:1351)NessusRed Hat Local Security Checks
high
62472RHEL 5 / 6 : firefox (RHSA-2012:1350)NessusRed Hat Local Security Checks
high