7.5
CVE-2012-0464
- EPSS 2.12%
- Published 14.03.2012 19:55:02
- Last modified 11.04.2025 00:51:21
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to execute arbitrary code via vectors involving an empty argument to the array.join function in conjunction with the triggering of garbage collection.
Data is provided by the National Vulnerability Database (NVD)
Mozilla ≫ Thunderbird Version >= 1.0 <= 3.1.19
Mozilla ≫ Thunderbird Version > 5.0 <= 10.0
Mozilla ≫ Thunderbird Esr Version10.0
Mozilla ≫ Thunderbird Esr Version10.0.1
Mozilla ≫ Thunderbird Esr Version10.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 2.12% | 0.834 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|