CVE-2012-0464: Use After Free
Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to execute arbitrary code via vectors involving an empty argument to the array.join function in conjunction with the triggering of garbage collection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0464?
The severity of CVE-2012-0464 is critical as it can allow remote attackers to execute arbitrary code on affected systems.
How do I fix CVE-2012-0464?
To fix CVE-2012-0464, update Mozilla Firefox, Thunderbird, or SeaMonkey to the latest versions that contain the security patches.
Which versions of software are affected by CVE-2012-0464?
CVE-2012-0464 affects Mozilla Firefox versions prior to 3.6.28, 4.x through 10.0, Mozilla Thunderbird versions prior to 3.1.20 and 5.0 through 10.0, and SeaMonkey versions prior to 2.8.
Can CVE-2012-0464 be exploited remotely?
Yes, CVE-2012-0464 can be exploited remotely, allowing attackers to gain control over target systems without physical access.
What should users do now regarding CVE-2012-0464?
Users should immediately update their Firefox, Thunderbird, or SeaMonkey browsers to mitigate the risk posed by CVE-2012-0464.