[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-3962Date: (C)2012-08-29   (M)2024-03-27


Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly iterate through the characters in a text run, which allows remote attackers to execute arbitrary code via a crafted document.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
DSA-2553
DSA-2554
DSA-2556
RHSA-2012:1210
RHSA-2012:1211
SUSE-SU-2012:1157
SUSE-SU-2012:1167
USN-1548-1
USN-1548-2
http://www.mozilla.org/security/announce/2012/mfsa2012-58.html
http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf
https://bugzilla.mozilla.org/show_bug.cgi?id=769120
openSUSE-SU-2012:1065
oval:org.mitre.oval:def:16494

CPE    342
cpe:/a:mozilla:firefox:14.0
cpe:/a:mozilla:firefox:1.5:beta2
cpe:/a:mozilla:thunderbird:11.0
cpe:/a:mozilla:firefox:1.5:beta1
...
OVAL    22
oval:org.secpod.oval:def:700980
oval:org.secpod.oval:def:700982
oval:org.secpod.oval:def:400428
oval:org.secpod.oval:def:400421
...

© SecPod Technologies