CVE-2012-0472: Buffer Overflow
The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9, when certain Windows Vista and Windows 7 configurations are used, does not properly restrict font-rendering attempts, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0472?
The severity of CVE-2012-0472 is classified as moderate.
How do I fix CVE-2012-0472?
To fix CVE-2012-0472, update affected software such as Mozilla Firefox, Thunderbird, or SeaMonkey to the latest versions.
Which versions are affected by CVE-2012-0472?
CVE-2012-0472 affects Mozilla Firefox versions 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey versions prior to 2.9 on specific Windows configurations.
Is CVE-2012-0472 a local or remote vulnerability?
CVE-2012-0472 can be exploited locally through special font configurations.
What are the potential impacts of CVE-2012-0472?
The potential impacts of CVE-2012-0472 include arbitrary code execution due to improper font rendering.