CVE-2012-0478: Critical severity firefox vulnerability
The texImage2D implementation in the WebGL subsystem in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 does not properly restrict JSVALTOOBJECT casts, which might allow remote attackers to execute arbitrary code via a crafted web page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0478?
CVE-2012-0478 is considered a moderate severity vulnerability that can potentially allow remote attackers to execute arbitrary code.
How do I fix CVE-2012-0478?
To address CVE-2012-0478, update your Mozilla Firefox, Thunderbird, or SeaMonkey software to the latest version available.
Which versions are affected by CVE-2012-0478?
CVE-2012-0478 affects Mozilla Firefox versions 4.0 through 11.0, Thunderbird versions 5.0 through 11.0, and SeaMonkey versions prior to 2.9.
What type of attack is enabled by CVE-2012-0478?
CVE-2012-0478 enables remote attackers to potentially conduct an arbitrary code execution attack through improper restriction of JSVAL_TO_OBJECT casts.
Is CVE-2012-0478 still a threat today?
While CVE-2012-0478 is an older vulnerability, it is essential for users of affected software to ensure they are running updated versions to mitigate any risks.