Sploitus

CVE-2012-3972

1 known exploit for CVE-2012-3972

The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based buffer over-read.

Mozilla Firefox
< 15.0, 10.0.7
Mozilla Seamonkey
< 2.12
Mozilla Thunderbird
< 15.0
Mozilla Thunderbird Esr
< 10.0.7
Fix
Available
CVSS 2.0
5.0 MEDIUM
EPSS
4.0% (89th percentile)
Weakness
CWE-200
NVD status
Modified
Published
2012-08-29
CVE-2012-3972 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2012-3972

Proof-of-concept code and exploit modules indexed by Sploitus