CVE-2012-0470: Buffer Overflow
Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::LightPixel function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (invalid gfxImageSurface free operation) or possibly execute arbitrary code by leveraging the use of "different number systems."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0470?
CVE-2012-0470 is classified as a high-severity vulnerability that can lead to denial of service.
How do I fix CVE-2012-0470?
To mitigate CVE-2012-0470, users should update to the latest versions of Mozilla Firefox, Thunderbird, or SeaMonkey that have addressed this issue.
What versions are affected by CVE-2012-0470?
CVE-2012-0470 affects Mozilla Firefox versions 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey versions before 2.9.
Can CVE-2012-0470 be exploited remotely?
Yes, CVE-2012-0470 can be exploited remotely by attackers, potentially causing a denial of service.
What is the nature of the vulnerability in CVE-2012-0470?
CVE-2012-0470 is a heap-based buffer overflow vulnerability in the nsSVGFEDiffuseLightingElement::LightPixel function.