CVE-2012-1954
Summary
| CVE | CVE-2012-1954 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-07-18 10:26:48 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Use-after-free vulnerability in the nsDocument::AdoptNode function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via vectors involving multiple adoptions and empty documents. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 10.0 | All | All | All |
| Application | Mozilla | Firefox | 10.0.1 | All | All | All |
| Application | Mozilla | Firefox | 10.0.2 | All | All | All |
| Application | Mozilla | Firefox | 10.0.3 | All | All | All |
| Application | Mozilla | Firefox | 10.0.4 | All | All | All |
| Application | Mozilla | Firefox | 10.0.5 | All | All | All |
| Application | Mozilla | Firefox | 11.0 | All | All | All |
| Application | Mozilla | Firefox | 12.0 | All | All | All |
| Application | Mozilla | Firefox | 12.0 | beta6 | All | All |
| Application | Mozilla | Firefox | 13.0 | All | All | All |
| Application | Mozilla | Firefox | 4.0 | All | All | All |
| Application | Mozilla | Firefox | 4.0 | beta1 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta10 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta11 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta12 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta2 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta3 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta4 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta5 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta6 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta7 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta8 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta9 | All | All |
| Application | Mozilla | Firefox | 4.0.1 | All | All | All |
| Application | Mozilla | Firefox | 5.0 | All | All | All |
| Application | Mozilla | Firefox | 5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 6.0 | All | All | All |
| Application | Mozilla | Firefox | 6.0.1 | All | All | All |
| Application | Mozilla | Firefox | 6.0.2 | All | All | All |
| Application | Mozilla | Firefox | 7.0 | All | All | All |
| Application | Mozilla | Firefox | 7.0.1 | All | All | All |
| Application | Mozilla | Firefox | 8.0 | All | All | All |
| Application | Mozilla | Firefox | 8.0.1 | All | All | All |
| Application | Mozilla | Firefox | 9.0 | All | All | All |
| Application | Mozilla | Firefox | 9.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | alpha | All | All |
| Application | Mozilla | Seamonkey | 1.0 | beta | All | All |
| Application | Mozilla | Seamonkey | 1.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.2 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.3 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.4 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.5 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.6 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.7 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.8 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.9 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1 | alpha | All | All |
| Application | Mozilla | Seamonkey | 1.1 | beta | All | All |
| Application | Mozilla | Seamonkey | 1.1.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.10 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.11 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.12 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.13 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.14 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.15 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.16 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.17 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.18 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.19 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.2 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.3 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.4 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.5 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.6 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.7 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.8 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.9 | All | All | All |
| Application | Mozilla | Seamonkey | 1.5.0.10 | All | All | All |
| Application | Mozilla | Seamonkey | 1.5.0.8 | All | All | All |
| Application | Mozilla | Seamonkey | 1.5.0.9 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_2 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_3 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | beta_1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | beta_2 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | rc1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | rc2 | All | All |
| Application | Mozilla | Seamonkey | 2.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.10 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.11 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.12 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.13 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.14 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.2 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.3 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.4 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.5 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.6 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.7 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.8 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.9 | All | All | All |
| Application | Mozilla | Seamonkey | 2.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.1 | alpha1 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | alpha2 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | alpha3 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | rc1 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | rc2 | All | All |
| Application | Mozilla | Seamonkey | All | All | All | All |
| Application | Mozilla | Thunderbird | 10.0 | All | All | All |
| Application | Mozilla | Thunderbird | 10.0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 10.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 10.0.3 | All | All | All |
| Application | Mozilla | Thunderbird | 10.0.4 | All | All | All |
| Application | Mozilla | Thunderbird | 11.0 | All | All | All |
| Application | Mozilla | Thunderbird | 12.0 | All | All | All |
| Application | Mozilla | Thunderbird | 13.0 | All | All | All |
| Application | Mozilla | Thunderbird | 5.0 | All | All | All |
| Application | Mozilla | Thunderbird | 6.0 | All | All | All |
| Application | Mozilla | Thunderbird | 6.0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 6.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 7.0 | All | All | All |
| Application | Mozilla | Thunderbird | 7.0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 8.0 | All | All | All |
| Application | Mozilla | Thunderbird | 9.0 | All | All | All |
| Application | Mozilla | Thunderbird | 9.0.1 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 10.0 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 10.0.1 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 10.0.2 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 10.0.3 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 10.0.4 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 10.0.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mozilla Thunderbird Multiple Bugs Let Remote Users Execute Arbitrary Code, Spoof Web Sites, Obtain Information, and Conduct Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Debian -- Security Information -- DSA-2514-1 iceweasel | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Mozilla Seamonkey Multiple Bugs Let Remote Users Execute Arbitrary Code, Spoof Web Sites, Obtain Information, and Conduct Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| [security-announce] SUSE-SU-2012:0896-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| USN-1509-2: ubufox update | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| USN-1510-1: Thunderbird vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Security Advisory SA49977 - Red Hat update for thunderbird - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Mozilla Firefox Multiple Bugs Let Remote Users Execute Arbitrary Code, Spoof Web Sites, Obtain Information, and Conduct Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| USN-1509-1: Firefox vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [security-announce] openSUSE-SU-2012:0917-1: important: MozillaThunderbi | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security Advisory SA49963 - Debian update for iceape - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA49968 - Ubuntu update for thunderbird - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| osvdb.org/83995 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Debian -- Security Information -- DSA-2528-1 icedove | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Mozilla Firefox, SeaMonkey, and Thunderbird Multiple Remote Memory Corruption Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 765139 – (CVE-2012-1954) Heap-use-after-free in nsDocument::AdoptNode | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| [security-announce] openSUSE-SU-2012:0899-1: critical: MozillaFirefox to | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| MFSA 2012-44: Gecko memory corruption | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| Security Advisory SA49964 - Debian update for iceweasel - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA49979 - Red Hat update for firefox - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA49972 - Ubuntu update for firefox - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [security-announce] SUSE-SU-2012:0895-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.