CVE-2012-0464
Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to execute arbitrary code via vectors involving an empty argument to the array.join function in conjunction with the triggering of garbage collection.
- Affected products
- Centos, Firefox Esr, Firefox, Red Hat, Seamonkey, Suse, Thunderbird, Thunderbird Esr
- Mozilla Firefox
- ≤ 3.6.27
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 4.0% (90th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2012-03-14
CVE-2012-0464 at NVD
No indexed exploits for CVE-2012-0464 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2012-0464 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.