PT-2012-2570 · Mozilla+3 · Firefox+5

Nicolas Grégoire

·

Published

2012-01-31

·

Updated

2024-12-12

·

CVE-2012-0449

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.6.26 and 4.x through 9.0 Thunderbird versions prior to 3.1.18 and 5.0 through 9.0 SeaMonkey versions prior to 2.7
Description The issue allows remote attackers to cause a denial of service, resulting in memory corruption and application crash, or possibly execute arbitrary code. This is achieved via a malformed XSLT stylesheet embedded in a document.
Recommendations For Mozilla Firefox versions prior to 3.6.26 and 4.x through 9.0, update to a version outside of the affected range to resolve the issue. For Thunderbird versions prior to 3.1.18 and 5.0 through 9.0, update to a version outside of the affected range to resolve the issue. For SeaMonkey versions prior to 2.7, update to a version outside of the affected range to resolve the issue.

Exploit

Fix

RCE

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2012_0079
CESA-2012_0080
CVE-2012-0449
DSA-2400-1
DSA-2402-1
DSA-2406-1
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:14572-1
RHSA-2012:0079
RHSA-2012:0080
RHSA-2012_0079
RHSA-2012_0080

Affected Products

Centos
Firefox
Red Hat
Seamonkey
Suse
Thunderbird