CVE-2012-0456: Infoleak
The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 might allow remote attackers to obtain sensitive information from process memory via vectors that trigger an out-of-bounds read.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0456?
CVE-2012-0456 has a moderate severity rating, allowing potential exposure of sensitive information.
How do I fix CVE-2012-0456?
To fix CVE-2012-0456, update Mozilla Firefox to version 3.6.28 or later, or upgrade to a newer version.
Which products are affected by CVE-2012-0456?
CVE-2012-0456 affects Mozilla Firefox versions before 3.6.28, Firefox ESR 10.x prior to 10.0.3, and specific versions of Thunderbird and SeaMonkey.
Can CVE-2012-0456 be exploited remotely?
Yes, CVE-2012-0456 can be exploited remotely to access sensitive information from affected applications.
Is there a patch available for CVE-2012-0456?
Yes, patches have been released for all affected versions to mitigate the vulnerability.