CVE-2012-0472
Summary
| CVE | CVE-2012-0472 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-04-25 10:10:17 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9, when certain Windows Vista and Windows 7 configurations are used, does not properly restrict font-rendering attempts, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 10.0 | All | All | All |
| Application | Mozilla | Firefox | 10.0.1 | All | All | All |
| Application | Mozilla | Firefox | 10.0.2 | All | All | All |
| Application | Mozilla | Firefox | 11.0 | All | All | All |
| Application | Mozilla | Firefox | 4.0 | All | All | All |
| Application | Mozilla | Firefox | 4.0 | beta1 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta10 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta11 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta12 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta2 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta3 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta4 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta5 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta6 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta7 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta8 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta9 | All | All |
| Application | Mozilla | Firefox | 4.0.1 | All | All | All |
| Application | Mozilla | Firefox | 5.0 | All | All | All |
| Application | Mozilla | Firefox | 6.0 | All | All | All |
| Application | Mozilla | Firefox | 6.0.1 | All | All | All |
| Application | Mozilla | Firefox | 6.0.2 | All | All | All |
| Application | Mozilla | Firefox | 7.0 | All | All | All |
| Application | Mozilla | Firefox | 7.0.1 | All | All | All |
| Application | Mozilla | Firefox | 8.0 | All | All | All |
| Application | Mozilla | Firefox | 8.0.1 | All | All | All |
| Application | Mozilla | Firefox | 9.0 | All | All | All |
| Application | Mozilla | Firefox | 9.0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mozilla Firefox/Thunderbird/SeaMonkey 'cairo-dwrite' CVE-2012-0472 Memory Corruption Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| mandriva.com | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| MFSA 2012-25: Potential memory corruption during font rendering using cairo-dwrite | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable, Permissions Required |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable, Permissions Required |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| www.mandriva.com | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| 744480 – (CVE-2012-0472) cairo_dwrite_font_face Memory Corruption Vulnerability [V-49y00m3lf2] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Issue Tracking |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.