9.3

CVE-2012-1938

Exploit

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 13.0, Thunderbird before 13.0, and SeaMonkey before 2.10 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) methodjit/ImmutableSync.cpp, (2) the JSObject::makeDenseArraySlow function in js/src/jsarray.cpp, and unknown other components.

Data is provided by the National Vulnerability Database (NVD)
MozillaFirefox Version < 13.0
MozillaSeamonkey Version < 2.10
MozillaThunderbird Version < 13.0
OpensuseOpensuse Version11.4
OpensuseOpensuse Version12.1
SuseLinux Enterprise Desktop Version10 Updatesp4
SuseLinux Enterprise Desktop Version11 Updatesp1
SuseLinux Enterprise Server Version10 Updatesp4
SuseLinux Enterprise Server Version11 Updatesp1
SuseLinux Enterprise Server Version11 Updatesp1 SwPlatformvmware
RedhatStorage Version2.0
RedhatEnterprise Linux Eus Version6.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.25% 0.774
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
http://www.securityfocus.com/bid/53796
Third Party Advisory
VDB Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=670317
Patch
Vendor Advisory
Exploit
Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=699594
Patch
Vendor Advisory
Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=716067
Patch
Vendor Advisory
Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=723773
Patch
Vendor Advisory
Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=723971
Patch
Vendor Advisory
Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=730415
Patch
Vendor Advisory
Exploit
Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=736012
Patch
Vendor Advisory
Exploit
Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=748948
Patch
Vendor Advisory
Issue Tracking