CVE-2012-0452

Description

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger failure of an nsXBLDocumentInfo::ReadPrototypeBindings function call, related to the cycle collectors access to a hash table containing a stale XBL binding.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.801

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Mozilla Firefox (x64) 10.0Windows
Multiple vulnerabilities affected in Mozilla Thunderbird 10.0Windows
Multiple vulnerabilities affected in Mozilla_Firefox 10.0Windows
Multiple vulnerabilities affected in SeaMonkey 2.7Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 10.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 10.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 10.0Windows
Vulnerabilities CVE-2012-0452 are fixed in Mozilla Firefox For Mac (110.0.1)Mac
Vulnerabilities CVE-2012-0452 are fixed in Mozilla Thunderbird For Mac 10.0.1Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 10.0Mac
Multiple Vulnerabilities are affected in Mozilla Thunderbird for Mac 10.0Mac
Multiple Vulnerabilities are affected in SeaMonkey For Mac 2.7Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343016Mozilla Firefox (x64) (132.0.2)
PATCH-315938Mozilla Thunderbird (68.12.0)
PATCH-343015Mozilla Firefox (132.0.2)
PATCH-341197SeaMonkey (2.53.19)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-611807Mozilla Thunderbird For Mac (142.0)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611807Mozilla Thunderbird For Mac (142.0)
PATCH-611088SeaMonkey For Mac (2.53.21)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234