CVE Database
/

CVE-2012-0463

Back to search

CVE-2012-0463

Published: Mar 14, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 does not check the validity of an instance after event dispatching, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, as demonstrated by Mobile Firefox on Android.

VendorProductVersions

n/a

n/a

affected
n/a

References

openSUSE-SU-2012:0417
vendor-advisory
x_refsource_SUSE
48402
third-party-advisory
x_refsource_SECUNIA
48624
third-party-advisory
x_refsource_SECUNIA
SUSE-SU-2012:0424
vendor-advisory
x_refsource_SUSE
48629
third-party-advisory
x_refsource_SECUNIA
SUSE-SU-2012:0425
vendor-advisory
x_refsource_SUSE
1026803
vdb-entry
x_refsource_SECTRACK
52466
vdb-entry
x_refsource_BID
48553
third-party-advisory
x_refsource_SECUNIA
48561
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:15143
vdb-entry
signature
x_refsource_OVAL
1026801
vdb-entry
x_refsource_SECTRACK
1026804
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now