CVE-2012-4187
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage a certain insPos variable, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and assertion failure) via unspecified vectors.
- Affected products
- Centos, Firefox Esr, Firefox, Red Hat, Seamonkey, Suse, Thunderbird, Thunderbird Esr
- Mozilla Firefox
- < 10.0.8
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 6.8% (93th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2012-10-10
CVE-2012-4187 at NVD
1 known exploit for CVE-2012-4187
Proof-of-concept code and exploit modules indexed by Sploitus