Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to execute arbitrary code via vectors involving an empty argument to the array.join function in conjunction with the triggering of garbage collection.
References
Link Providers
http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00014.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00015.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-updates/2012-03/msg00042.html cve-icon cve-icon
http://pwn2own.zerodayinitiative.com/status.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2012-0387.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2012-0388.html cve-icon cve-icon
http://secunia.com/advisories/48359 cve-icon cve-icon
http://secunia.com/advisories/48402 cve-icon cve-icon
http://secunia.com/advisories/48414 cve-icon cve-icon
http://secunia.com/advisories/48495 cve-icon cve-icon
http://secunia.com/advisories/48496 cve-icon cve-icon
http://secunia.com/advisories/48513 cve-icon cve-icon
http://secunia.com/advisories/48553 cve-icon cve-icon
http://secunia.com/advisories/48561 cve-icon cve-icon
http://secunia.com/advisories/48624 cve-icon cve-icon
http://secunia.com/advisories/48629 cve-icon cve-icon
http://secunia.com/advisories/48823 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2012:031 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2012:032 cve-icon cve-icon
http://www.mozilla.org/security/announce/2012/mfsa2012-19.html cve-icon cve-icon
http://www.securityfocus.com/bid/52465 cve-icon cve-icon
http://www.securitytracker.com/id?1026801 cve-icon cve-icon
http://www.securitytracker.com/id?1026803 cve-icon cve-icon
http://www.securitytracker.com/id?1026804 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-1400-1 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-1400-2 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-1400-3 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-1400-4 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-1400-5 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-1401-1 cve-icon cve-icon
http://www.zdnet.com/blog/security/mozilla-knew-of-pwn2own-bug-before-cansecwest/10757 cve-icon cve-icon
http://www.zdnet.com/blog/security/researchers-hack-into-newest-firefox-with-zero-day-flaw/10663 cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=720079 cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=735104 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2012-0464 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14170 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2012-0464 cve-icon
History

Mon, 21 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mozilla:firefox_esr:10.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:10.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:10.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:10.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:10.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:10.0:*:*:*:*:*:*:*
Vendors & Products Mozilla firefox Esr

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2012-03-14T19:00:00

Updated: 2024-08-06T18:23:30.994Z

Reserved: 2012-01-09T00:00:00

Link: CVE-2012-0464

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2012-03-14T19:55:02.337

Modified: 2024-11-21T01:35:02.347

Link: CVE-2012-0464

cve-icon Redhat

Severity : Critical

Publid Date: 2012-03-13T00:00:00Z

Links: CVE-2012-0464 - Bugzilla