CVE-2012-3988: Use After Free
Use-after-free vulnerability in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 might allow user-assisted remote attackers to execute arbitrary code via vectors involving use of mozRequestFullScreen to enter full-screen mode, and use of the history.back method for backwards history navigation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3988?
CVE-2012-3988 has a critical severity level as it could allow remote attackers to execute arbitrary code.
How do I fix CVE-2012-3988?
To fix CVE-2012-3988, users should upgrade to a patched version of Mozilla Firefox, Thunderbird, or SeaMonkey, specifically version 16.0 or later.
Which software versions are affected by CVE-2012-3988?
CVE-2012-3988 affects Mozilla Firefox before version 16.0, Thunderbird before version 16.0, and SeaMonkey before version 2.13.
How does CVE-2012-3988 exploit the use-after-free vulnerability?
CVE-2012-3988 exploits the use-after-free vulnerability through vectors involving the mozRequestFullScreen method.
Are there any operating systems affected by CVE-2012-3988?
Yes, CVE-2012-3988 affects multiple versions of Ubuntu and Red Hat Enterprise Linux that include the vulnerable software.