CVE-2012-0457: Use After Free
Use-after-free vulnerability in the nsSMILTimeValueSpec::ConvertBetweenTimeContainer function in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 might allow remote attackers to execute arbitrary code via an SVG animation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0457?
CVE-2012-0457 has been classified as a critical vulnerability enabling potential arbitrary code execution.
How do I fix CVE-2012-0457?
To mitigate CVE-2012-0457, users should upgrade to the latest version of Mozilla Firefox, Thunderbird, or SeaMonkey as applicable.
What versions of Firefox are affected by CVE-2012-0457?
CVE-2012-0457 affects Firefox versions prior to 3.6.28 and versions 4.0 through 10.0.
What versions of Thunderbird are impacted by CVE-2012-0457?
CVE-2012-0457 impacts Thunderbird versions earlier than 3.1.20 and 5.0 through 10.0.
Which SeaMonkey versions are vulnerable to CVE-2012-0457?
CVE-2012-0457 affects SeaMonkey versions prior to 2.8.