10
CVSSv2

CVE-2012-0444

Published: 01/02/2012 Updated: 28/08/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Mozilla Firefox prior to 3.6.26 and 4.x up to and including 9.0, Thunderbird prior to 3.1.18 and 5.0 up to and including 9.0, and SeaMonkey prior to 2.7 do not properly initialize nsChildView data structures, which allows remote malicious users to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla seamonkey

mozilla thunderbird

debian debian linux 5.0

debian debian linux 6.0

opensuse opensuse 11.4

suse linux enterprise desktop 10

suse linux enterprise desktop 11

suse linux enterprise server 10

suse linux enterprise server 11

suse linux enterprise software development kit 10

suse linux enterprise software development kit 11

canonical ubuntu linux 10.04

canonical ubuntu linux 10.10

canonical ubuntu linux 11.04

canonical ubuntu linux 11.10

Vendor Advisories

Debian Bug report logs - #669196 libvorbisidec: multiple longstanding unfixed security issues in libvorbis Package: libvorbisidec; Maintainer for libvorbisidec is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Wed, 18 Apr 2012 03:21:01 UTC ...
Synopsis Important: libvorbis security update Type/Severity Security Advisory: Important Topic Updated libvorbis packages that fix one security issue are now availablefor Red Hat Enterprise Linux 4, 5, and 6The Red Hat Security Response Team has rated this update as havingimportant security impact A Commo ...
Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic Updated firefox packages that fix multiple security issues are nowavailable for Red Hat Enterprise Linux 4, 5, and 6The Red Hat Security Response Team has rated this update as having criticalsecurity impact Common V ...
Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox The included XULRunner library provides rendering services for several other applications included in Debian CVE-2011-3670 Gregory Fleischer discovered that IPv6 URLs were incorrectly parsed, resulting in potential information disclosure CVE-2012-044 ...
Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey: CVE-2011-3670 Gregory Fleischer discovered that IPv6 URLs were incorrectly parsed, resulting in potential information disclosure CVE-2012-0442 Jesse Ruderman and Bob Clary discovered memory corruption bugs, which may lead to the ex ...
It was discovered that a heap overflow in the Vorbis audio compression library could lead to the execution of arbitrary code if a malformed Ogg Vorbis file is processed For the stable distribution (squeeze), this problem has been fixed in version 131-1+squeeze1 For the unstable distribution (sid), this problem will be fixed soon We recommend t ...
A heap-based buffer overflow flaw was found in the way the libvorbis library parsed Ogg Vorbis media files If a specially-crafted Ogg Vorbis media file was opened by an application using libvorbis, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application (CVE-2012-0444) ...
Mozilla Foundation Security Advisory 2012-07 Potential Memory Corruption When Decoding Ogg Vorbis files Announced January 31, 2012 Reporter regenrecht Impact Critical Products Firefox, SeaMonkey, Thunderbird Fixed in ...
libvorbis could be made to crash or run programs as your login if it opened a specially crafted file ...
Several security issues were fixed in Thunderbird ...
Several security issues were fixed in Firefox ...
Several security issues were fixed in Xulrunner ...
This update provides compatible ubufox and webfav packages for the latest Firefox ...
This update provides compatible Mozvoikko packages for the latest Firefox ...
Several security issues were fixed in Thunderbird ...