Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2400-1 | iceweasel security update |
Debian DSA |
DSA-2402-1 | iceape security update |
Debian DSA |
DSA-2406-1 | icedove security update |
Debian DSA |
DSA-2412-1 | libvorbis security update |
EUVD |
EUVD-2012-0476 | Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file. |
Ubuntu USN |
USN-1350-1 | Thunderbird vulnerabilities |
Ubuntu USN |
USN-1353-1 | Xulrunnner vulnerabilities |
Ubuntu USN |
USN-1355-1 | Firefox vulnerabilities |
Ubuntu USN |
USN-1369-1 | Thunderbird vulnerabilities |
Ubuntu USN |
USN-1370-1 | libvorbis vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T18:23:31.006Z
Reserved: 2012-01-09T00:00:00
Link: CVE-2012-0444
No data.
Status : Deferred
Published: 2012-02-01T16:55:01.007
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-0444
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN