CVE-2012-4215
- EPSS 4.32%
- Published 21.11.2012 12:55:02
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in the nsPlaintextEditor::FireClipboardEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote ...
CVE-2012-4216
- EPSS 6.39%
- Published 21.11.2012 12:55:02
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in the gfxFont::GetFontEntry function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to exe...
CVE-2012-4217
- EPSS 2.87%
- Published 21.11.2012 12:55:02
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap ...
- EPSS 2.16%
- Published 21.11.2012 12:55:02
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in the BuildTextRunsScanner::BreakSink::SetBreaks function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service ...
CVE-2012-4201
- EPSS 2.61%
- Published 21.11.2012 12:55:01
- Last modified 11.04.2025 00:51:21
The evalInSandbox implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 uses an incorrect context during the handling of JavaScript code...
CVE-2012-4202
- EPSS 6.75%
- Published 21.11.2012 12:55:01
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attacker...
CVE-2012-4203
- EPSS 2.47%
- Published 21.11.2012 12:55:01
- Last modified 11.04.2025 00:51:21
The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScript code by bookmarklets, which allows user-assisted remote attackers to run arbitrary programs by leveraging a javascript: URL in a bookmark.
CVE-2012-4204
- EPSS 3.01%
- Published 21.11.2012 12:55:01
- Last modified 11.04.2025 00:51:21
The str_unescape function in the JavaScript engine in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application cr...
CVE-2012-4205
- EPSS 0.88%
- Published 21.11.2012 12:55:01
- Last modified 11.04.2025 00:51:21
Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XMLHttpRequest objects created in sandboxes, which allows remote attackers to conduct cross-site reques...
CVE-2012-4206
- EPSS 0.17%
- Published 21.11.2012 12:55:01
- Last modified 11.04.2025 00:51:21
Untrusted search path vulnerability in the installer in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 on Windows allows local users to gain privileges via a Trojan horse DLL in the default downloads directory.