CVE-2012-5836: Code Injection
Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving the setting of Cascading Style Sheets (CSS) properties in conjunction with SVG text.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5836?
CVE-2012-5836 has a high severity rating as it allows remote code execution or denial of service through manipulated CSS properties in SVG text.
How do I fix CVE-2012-5836?
To fix CVE-2012-5836, upgrade to Mozilla Firefox version 17.0 or later, Thunderbird version 17.0 or later, or SeaMonkey version 2.14 or later.
Which software is affected by CVE-2012-5836?
CVE-2012-5836 affects Mozilla Firefox versions prior to 17.0, Thunderbird versions prior to 17.0, SeaMonkey versions prior to 2.14, and certain versions of openSUSE and Ubuntu.
Can CVE-2012-5836 lead to data breaches?
Yes, CVE-2012-5836 can potentially lead to data breaches since it allows for arbitrary code execution by attackers.
What should I do if I cannot update due to compatibility issues with CVE-2012-5836?
If unable to update due to compatibility issues, consider implementing additional security measures such as using a different browser or disabling JavaScript.