RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2012-74 through -87 Multiple Vulnerabilities

BID:55856

Info

RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2012-74 through -87 Multiple Vulnerabilities

Bugtraq ID: 55856
Class: Unknown
CVE:
Remote: Yes
Local: Yes
Published: Oct 10 2012 12:00AM
Updated: May 07 2015 05:15PM
Credit: Henrik Skupin, Jesse Ruderman, moz_bug_r_a4, Christian Holler, Jesse Ruderman, David Bloom of Cue, Jordi Chancel, Collin Jackson, Warren He, Ms2ger, Alice White, Mariusz Mlynski, Mariusz Mlynski, Soroush Dalili, Ms2ger, Alice White, Mariusz Mlynski, Abhi
Vulnerable: Ubuntu Ubuntu Linux 12.04 LTS i386
Ubuntu Ubuntu Linux 12.04 LTS amd64
Ubuntu Ubuntu Linux 11.10 i386
Ubuntu Ubuntu Linux 11.10 amd64
Ubuntu Ubuntu Linux 11.04 powerpc
Ubuntu Ubuntu Linux 11.04 i386
Ubuntu Ubuntu Linux 11.04 ARM
Ubuntu Ubuntu Linux 11.04 amd64
Ubuntu Ubuntu Linux 10.04 sparc
Ubuntu Ubuntu Linux 10.04 powerpc
Ubuntu Ubuntu Linux 10.04 i386
Ubuntu Ubuntu Linux 10.04 ARM
Ubuntu Ubuntu Linux 10.04 amd64
S.u.S.E. openSUSE 12.1
S.u.S.E. openSUSE 11.4
Redhat Enterprise Linux Workstation Optional 6
Redhat Enterprise Linux Workstation 6
Redhat Enterprise Linux Server Optional 6
Redhat Enterprise Linux Server 6
Redhat Enterprise Linux Optional Productivity Application 5 server
Redhat Enterprise Linux HPC Node Optional 6
Redhat Enterprise Linux Desktop Workstation 5 client
Redhat Enterprise Linux Desktop Optional 6
Redhat Enterprise Linux Desktop 6
Redhat Enterprise Linux Desktop 5 client
Redhat Enterprise Linux 5 Server
Oracle Enterprise Linux 6.2
Oracle Enterprise Linux 6
Mozilla Thunderbird ESR 10.0.5
Mozilla Thunderbird ESR 10.0.4
Mozilla Thunderbird ESR 10.0.3
Mozilla Thunderbird ESR 10.0.7
Mozilla Thunderbird ESR 10.0.6
Mozilla Thunderbird ESR 10.0.2
Mozilla Thunderbird 3.1.20
Mozilla Thunderbird 3.1.14
Mozilla Thunderbird 3.1.13
Mozilla Thunderbird 3.1.12
Mozilla Thunderbird 3.1.7
Mozilla Thunderbird 3.1.5
Mozilla Thunderbird 3.1.4
Mozilla Thunderbird 3.0.11
Mozilla Thunderbird 3.0.9
Mozilla Thunderbird 3.0.9
Mozilla Thunderbird 3.0.8
Mozilla Thunderbird 3.0.5
Mozilla Thunderbird 3.0.4
Mozilla Thunderbird 3.0.2
Mozilla Thunderbird 9.0
Mozilla Thunderbird 8.0
Mozilla Thunderbird 7.0.1
Mozilla Thunderbird 7.0
Mozilla Thunderbird 6.0.2
Mozilla Thunderbird 6.0.1
Mozilla Thunderbird 6.0
Mozilla Thunderbird 6
Mozilla Thunderbird 6
Mozilla Thunderbird 5.0
Mozilla Thunderbird 5
Mozilla Thunderbird 3.3
Mozilla Thunderbird 3.3
Mozilla Thunderbird 3.1.9
Mozilla Thunderbird 3.1.8
Mozilla Thunderbird 3.1.7
Mozilla Thunderbird 3.1.6
Mozilla Thunderbird 3.1.3
Mozilla Thunderbird 3.1.2
Mozilla Thunderbird 3.1.19
Mozilla Thunderbird 3.1.18
Mozilla Thunderbird 3.1.18
Mozilla Thunderbird 3.1.17
Mozilla Thunderbird 3.1.16
Mozilla Thunderbird 3.1.15
Mozilla Thunderbird 3.1.11
Mozilla Thunderbird 3.1.10
Mozilla Thunderbird 3.1.1
Mozilla Thunderbird 3.1
Mozilla Thunderbird 3.0.7
Mozilla Thunderbird 3.0.6
Mozilla Thunderbird 3.0.4
Mozilla Thunderbird 3.0.3
Mozilla Thunderbird 15
Mozilla Thunderbird 14.0
Mozilla Thunderbird 14
Mozilla Thunderbird 13.0
Mozilla Thunderbird 12.0
Mozilla Thunderbird 11.0
Mozilla Thunderbird 10.0.2
Mozilla Thunderbird 10.0.1
Mozilla Thunderbird 10.0
Mozilla SeaMonkey 2.9
Mozilla SeaMonkey 2.8
Mozilla SeaMonkey 2.7.2
Mozilla SeaMonkey 2.7.1
Mozilla SeaMonkey 2.7
Mozilla SeaMonkey 2.6
Mozilla SeaMonkey 2.5
Mozilla SeaMonkey 2.4
Mozilla SeaMonkey 2.3
Mozilla SeaMonkey 2.2
Mozilla SeaMonkey 2.1b2
Mozilla SeaMonkey 2.12
Mozilla SeaMonkey 2.11
Mozilla SeaMonkey 2.11
Mozilla SeaMonkey 2.10
Mozilla SeaMonkey 2.1 Alpha3
Mozilla SeaMonkey 2.1 Alpha2
Mozilla SeaMonkey 2.1 Alpha1
Mozilla SeaMonkey 2.1
Mozilla Firefox 15.0.1
Mozilla Firefox 9.0.1
Mozilla Firefox 9.0
Mozilla Firefox 8.0.1
Mozilla Firefox 8.0
Mozilla Firefox 7.0.1
Mozilla Firefox 7.0
Mozilla Firefox 6.0.2
Mozilla Firefox 6.0.1
Mozilla Firefox 6.0
Mozilla Firefox 6
Mozilla Firefox 5.0.1
Mozilla Firefox 5.0
Mozilla Firefox 15
Mozilla Firefox 14.01
Mozilla Firefox 14
Mozilla Firefox 13.0
Mozilla Firefox 12.0
Mozilla Firefox 11.0
Mozilla Firefox 10.0.2
Mozilla Firefox 10.0.1
Mozilla Firefox 10.0
Mozilla Firefox 10
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
CentOS CentOS 5
Not Vulnerable: Mozilla Thunderbird ESR 10.0.8
Mozilla Thunderbird 16
Mozilla SeaMonkey 2.13
Mozilla Firefox ESR 10.0.8
Mozilla Firefox 16

Discussion

RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2012-74 through -87 Multiple Vulnerabilities

The Mozilla Foundation has released multiple security advisories specifying vulnerabilities in Mozilla Firefox, Thunderbird, and SeaMonkey.

These vulnerabilities allow attackers to execute arbitrary script or HTML code, steal cookie-based authentication credentials, conduct phishing attacks, execute arbitrary code in the context of the vulnerable application, crash affected applications, obtain potentially sensitive information, gain escalated privileges, bypass security restrictions, and perform unauthorized actions; other attacks may also be possible.

These issues are fixed in:

Firefox 16
Firefox ESR 10.0.8
Thunderbird 16
Thunderbird ESR 10.0.8
SeaMonkey 2.13

This BID is being retired. The following individual records exist to better document the issues:

55922 Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-3986 Multiple Security Bypass Vulnerabilities
55924 Mozilla Firefox/Thunderbird/Seamonkey CVE-2012-3982 Memory Corruption Vulnerability
56145 Mozilla Firefox/Thunderbird/Seamonkey CVE-2012-3983 Memory Corruption Vulnerability
55926 Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-3985 Security Bypass Vulnerability
55927 Mozilla Firefox/SeaMonkey/Thunderbird CVE-2012-3989 Denial of Service Vulnerability
55929 Mozilla Firefox CVE-2012-3987 Cross Site Scripting Vulnerability
55930 Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-3991 Security Bypass Vulnerability
55931 Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-3988 Use After Free Denial of Service Vulnerability
55932 Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-3984 Address Bar URI Spoofing Vulnerability
56136 Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-3995 Remote Code Execution Vulnerability
56140 Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-4183 Use After Free Memory Corruption Vulnerability
56129 Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-4179 Use After Free Memory Corruption Vulnerability
56135 Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-4186 Remote Buffer Overflow Vulnerability
56126 Mozilla Firefox/Thunderbird/Seamonkey CVE-2012-4180 Buffer Overflow Vulnerability
56123 Mozilla Firefox/Thunderbird/Seamonkey CVE-2012-4188 Buffer Overflow Vulnerability
56121 Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-4182 Remote Code Execution Vulnerability
56128 Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-3992 Security Vulnerability
56131 Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-3990 Use After Free Memory Corruption Vulnerability
56130 Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-4181 Use After Free Memory Corruption Vulnerability
56125 Mozilla Firefox/Thunderbird/SeaMonkey CVE-2012-4187 Heap Memory Corruption Vulnerability
56127 Mozilla Firefox/Thunderbird/Seamonkey CVE-2012-4185 Buffer Overflow Vulnerability
56120 Mozilla Firefox/Thunderbird/Seamonkey CVE-2012-4184 Arbitrary Code Execution Vulnerability
56119 Mozilla Firefox/Thunderbird/Seamonkey CVE-2012-3993 Arbitrary Code Execution Vulnerability
56118 Mozilla Firefox/SeaMonkey/Thunderbird CVE-2012-3994 Cross Site Scripting Vulnerability

Exploit / POC

RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2012-74 through -87 Multiple Vulnerabilities

Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

Some of these issues may not require specific exploit code and may be trivial to exploit.

Solution / Fix

RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2012-74 through -87 Multiple Vulnerabilities

Solution:
Updates are available. Please see the references for more information.


MandrakeSoft Enterprise Server 5

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report