CVE-2012-3985
- EPSS 0.92%
- Veröffentlicht 10.10.2012 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access af...
CVE-2012-3986
- EPSS 0.84%
- Veröffentlicht 10.10.2012 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils) methods, which allows remote a...
CVE-2012-3988
- EPSS 3.99%
- Veröffentlicht 10.10.2012 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 might allow user-assisted remote attackers to execute arbitrary code v...
CVE-2012-3989
- EPSS 0.85%
- Veröffentlicht 10.10.2012 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly perform a cast of an unspecified variable during use of the instanceof operator on a JavaScript object, which allows remote attackers to execute arbitrary...
CVE-2012-3990
- EPSS 6.07%
- Veröffentlicht 10.10.2012 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to exe...
CVE-2012-3991
- EPSS 1.42%
- Veröffentlicht 10.10.2012 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which allows remote attackers to by...
CVE-2012-3489
- EPSS 0.96%
- Veröffentlicht 03.10.2012 21:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or U...
CVE-2012-3400
- EPSS 4.78%
- Veröffentlicht 03.10.2012 11:02:56
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in the udf_load_logicalvol function in fs/udf/super.c in the Linux kernel before 3.4.5 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted UDF filesyst...
CVE-2012-3412
- EPSS 9.14%
- Veröffentlicht 03.10.2012 11:02:56
- Zuletzt bearbeitet 11.04.2025 00:51:21
The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption and network-controller outage) via crafted TCP packets that trigger a small MSS value.
CVE-2012-3955
- EPSS 12.1%
- Veröffentlicht 14.09.2012 10:33:21
- Zuletzt bearbeitet 11.04.2025 00:51:21
ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circumstances by establishing an IPv6 lease in an environment where the lease expiration time is later red...