CVE-2012-1946: Use After Free
Use-after-free vulnerability in the nsINode::ReplaceOrInsertBefore function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 might allow remote attackers to execute arbitrary code via document changes involving replacement or insertion of a node.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1946?
CVE-2012-1946 has been classified as a critical vulnerability due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2012-1946?
To address CVE-2012-1946, users should update to the latest version of Mozilla Firefox, Thunderbird, or SeaMonkey as applicable.
Which versions are affected by CVE-2012-1946?
CVE-2012-1946 affects Mozilla Firefox versions 4.x through 12.0, Thunderbird versions 5.0 through 12.0, and various versions of SeaMonkey.
Can CVE-2012-1946 be exploited without user interaction?
Yes, CVE-2012-1946 can potentially be exploited remotely without any user interaction, making it particularly dangerous.
Is CVE-2012-1946 specific to certain operating systems?
CVE-2012-1946 does not specify operating systems, but affects the applications on platforms where they are run.