CVE-2012-0467
Summary
| CVE | CVE-2012-0467 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-04-25 10:10:17 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 10.0 | All | All | All |
| Application | Mozilla | Firefox | 10.0.1 | All | All | All |
| Application | Mozilla | Firefox | 10.0.2 | All | All | All |
| Application | Mozilla | Firefox | 11.0 | All | All | All |
| Application | Mozilla | Firefox | 4.0 | All | All | All |
| Application | Mozilla | Firefox | 4.0 | beta1 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta10 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta11 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta12 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta2 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta3 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta4 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta5 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta6 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta7 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta8 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta9 | All | All |
| Application | Mozilla | Firefox | 4.0.1 | All | All | All |
| Application | Mozilla | Firefox | 5.0 | All | All | All |
| Application | Mozilla | Firefox | 5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 6.0 | All | All | All |
| Application | Mozilla | Firefox | 6.0.1 | All | All | All |
| Application | Mozilla | Firefox | 6.0.2 | All | All | All |
| Application | Mozilla | Firefox | 7.0 | All | All | All |
| Application | Mozilla | Firefox | 7.0.1 | All | All | All |
| Application | Mozilla | Firefox | 8.0 | All | All | All |
| Application | Mozilla | Firefox | 8.0.1 | All | All | All |
| Application | Mozilla | Firefox | 9.0 | All | All | All |
| Application | Mozilla | Firefox | 9.0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 708825 – "ASSERTION: Fault in cycle collector: traversed refs exceed refcount" closing window nearScriptStackLimit | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 737384 – Assertion failure: thing, at js/src/jsgcmark.cpp:7 or Crash [@ js::gc::MarkInternal] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 723453 – Heap overrun (read + write) in nsBMPEncoder::ConvertHostARGBRow | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 736609 – Malloc error with ArrayBuffer, Uint32Array and Uint8Array | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 737875 – OOM Crash [@ nsQueryInterfaceWithError::operator] trying to execute random memory | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| mandriva.com | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Debian -- Security Information -- DSA-2464-2 icedove | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| 720305 – "Assertion failure: compartment mismatched" with nodelist, custom length setter | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 735943 – Crash @ nsCSSFrameConstructor::ProcessPendingRestyles | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 732941 – OOM Crash [@ nsCOMArray<nsISelectionListener>::operator[]] due to unhandled alloc failure in nsTypedSelection::NotifySelectionListeners | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Security Advisory SA48922 - Debian update for iceweasel - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-0467 Memory Corruption Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 736589 – Crash [@ nsDOMStorage::GetNamedItem] with sessionStorage, GC | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 726502 – nsDeviceMotion::DeviceMotionChanged may index out of bounds mWindowListeners array | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Debian -- Security Information -- DSA-2457-2 iceweasel | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| 733979 – Opt-only Crash [@ js::gc::MarkInternal] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| MFSA 2012-20: Miscellaneous memory safety hazards (rv:12.0/ rv:10.0.4) | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| 735073 – Plugins can be fooled by window.location (again) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 732951 – EnsureMutable() returns true (success) even when it failed due to OOM | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 740595 – "Assertion failure: [infer failure] Missing type pushed 0:" | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 714614 – Assertion failure: self->nativeContains(cx, *aprop), at jsscope.cpp:1000 | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 706381 – Java related crash with deleted pointer in esx | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Security Advisory SA48920 - Debian update for iceape - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 726332 – nsFormFillController's MutationObserver handling is suspicious | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 716556 – Potential buffer overflow in nsScriptableInputStream::Read with 4GB data | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 733282 – Crash in nsHtml5TreeBuilder | ASSERTION: The Unicode decoder wrote too much data.: 'end <= NS_HTML5_STREAM_PARSER_READ_BUFFER_SIZE' | ASSERTION: The decoder signaled an error other than NS_ERROR_ILLEGAL_INPUT.: 'convResult == NS_ERROR_ILLEGAL_INPUT' | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Debian -- Security Information -- DSA-2458-2 iceape | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| 680456 – Don't run compileAndGo scripts on globals with a cleared scope | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 737129 – Possible Exploitable Crashes with Low Memory [@ nsiNodeInfo::NodeInfoManager ] with js::mjit::EnterMethodJIT on the stack | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 737182 – 2D texture corruption on Mac/Intel with large texture sizes >= 4993 | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| www.mandriva.com | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.