CVE-2012-4215: Use After Free
Published Nov 21, 2012
·Updated
Use-after-free vulnerability in the nsPlaintextEditor::FireClipboardEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
Affected Software
27 affected components
Mozilla Firefox<10.0.11
Mozilla Firefox<17.0
Mozilla SeaMonkey<2.14
Mozilla Thunderbird<17.0
Mozilla Thunderbird ESR<10.0.11
openSUSE openSUSE=11.4
openSUSE openSUSE=12.1
openSUSE openSUSE=12.2
SUSE Linux Enterprise Desktop=10-sp4
SUSE Linux Enterprise Desktop=11-sp2
SUSE Linux Enterprise Server=10-sp4
SUSE Linux Enterprise Server=11-sp2
SUSE Linux Enterprise Server Vmware=11-sp2
SUSE Linux Enterprise Software Development Kit=10-sp4
SUSE Linux Enterprise Software Development Kit=11-sp2
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=11.10
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=12.10
redhat Enterprise Linux Desktop=5.0
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Eus=6.3
redhat Enterprise Linux Server=5.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Workstation=5.0
redhat Enterprise Linux Workstation=6.0
Mozilla Firefox ESR<10.0.11
Remediation
Patch Available
Event History
Nov 21, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
Is CVE-2012-4215 still a concern for current users?
While CVE-2012-4215 is an older vulnerability, users of legacy software versions should remain aware of its potential risks until they upgrade.