9.3
CVE-2012-1139
- EPSS 2.97%
- Veröffentlicht 25.04.2012 10:10:18
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or possibly execute arbitrary code via crafted glyph data in a BDF font.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Mobile Version <= 10.0.3
Mozilla ≫ Firefox Mobile Version1.0
Mozilla ≫ Firefox Mobile Version4.0
Mozilla ≫ Firefox Mobile Version4.0 Updatebeta1
Mozilla ≫ Firefox Mobile Version4.0 Updatebeta2
Mozilla ≫ Firefox Mobile Version4.0 Updatebeta3
Mozilla ≫ Firefox Mobile Version4.0 Updatebeta4
Mozilla ≫ Firefox Mobile Version5.0
Mozilla ≫ Firefox Mobile Version6.0
Mozilla ≫ Firefox Mobile Version6.0.1
Mozilla ≫ Firefox Mobile Version6.0.2
Mozilla ≫ Firefox Mobile Version7.0
Mozilla ≫ Firefox Mobile Version8.0
Mozilla ≫ Firefox Mobile Version9.0
Mozilla ≫ Firefox Mobile Version10.0
Mozilla ≫ Firefox Mobile Version10.0.1
Mozilla ≫ Firefox Mobile Version10.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 2.97% | 0.852 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.