Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly iterate through the characters in a text run, which allows remote attackers to execute arbitrary code via a crafted document.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Information
Published : 2012-08-29 03:56
Updated : 2017-09-18 18:35
NVD link : CVE-2012-3962
Mitre link : CVE-2012-3962
JSON object : View
CWE
Products Affected
mozilla
- firefox_esr
- thunderbird
- firefox
- thunderbird_esr
- seamonkey