CVE-2012-1971
Last modified
CVE-2012-1971 is a vulnerability of currently unknown severity. Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to garbage collection after certain MethodJIT execution, and unknown other vectors.. EPSS estimates a 3.81% chance of exploitation in the next 30 days.
Description
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to garbage collection after certain MethodJIT execution, and unknown other vectors.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | <= 14.0 |
| Mozilla | Firefox | 1.0 |
| Mozilla | Firefox | 1.0.1 |
| Mozilla | Firefox | 1.0.2 |
| Mozilla | Firefox | 1.0.3 |
| Mozilla | Firefox | 1.0.4 |
| Mozilla | Firefox | 1.0.5 |
| Mozilla | Firefox | 1.0.6 |
| Mozilla | Firefox | 1.0.7 |
| Mozilla | Firefox | 1.0.8 |
| Mozilla | Firefox | 1.4.1 |
| Mozilla | Firefox | 1.5 |
| Mozilla | Firefox | 1.5.0.1 |
| Mozilla | Firefox | 1.5.0.2 |
| Mozilla | Firefox | 1.5.0.3 |
| Mozilla | Firefox | 1.5.0.4 |
| Mozilla | Firefox | 1.5.0.5 |
| Mozilla | Firefox | 1.5.0.6 |
| Mozilla | Firefox | 1.5.0.7 |
| Mozilla | Firefox | 1.5.0.8 |
| Mozilla | Firefox | 1.5.0.9 |
| Mozilla | Firefox | 1.5.0.10 |
| Mozilla | Firefox | 1.5.0.11 |
| Mozilla | Firefox | 1.5.0.12 |
| Mozilla | Firefox | 1.5.1 |
| Mozilla | Firefox | 1.5.2 |
| Mozilla | Firefox | 1.5.3 |
| Mozilla | Firefox | 1.5.4 |
| Mozilla | Firefox | 1.5.5 |
| Mozilla | Firefox | 1.5.6 |
| Mozilla | Firefox | 1.5.7 |
| Mozilla | Firefox | 1.5.8 |
| Mozilla | Firefox | 1.8 |
| Mozilla | Firefox | 2.0 |
| Mozilla | Firefox | 2.0.0.1 |
| Mozilla | Firefox | 2.0.0.2 |
| Mozilla | Firefox | 2.0.0.3 |
| Mozilla | Firefox | 2.0.0.4 |
| Mozilla | Firefox | 2.0.0.5 |
| Mozilla | Firefox | 2.0.0.6 |
| Mozilla | Firefox | 2.0.0.7 |
| Mozilla | Firefox | 2.0.0.8 |
| Mozilla | Firefox | 2.0.0.9 |
| Mozilla | Firefox | 2.0.0.10 |
| Mozilla | Firefox | 2.0.0.11 |
| Mozilla | Firefox | 2.0.0.12 |
| Mozilla | Firefox | 2.0.0.13 |
| Mozilla | Firefox | 2.0.0.14 |
| Mozilla | Firefox | 2.0.0.15 |
| Mozilla | Firefox | 2.0.0.16 |
Showing 50 of 264 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-1971?
How severe is CVE-2012-1971?
How do I fix CVE-2012-1971?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-1965Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before…
- CVE-2012-1966Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before…
- CVE-2012-1967Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10…
- CVE-2012-1968Bugzilla 4.1.x and 4.2.x before 4.2.2 and 4.3.x before 4.3.2…
- CVE-2012-1969The get_attachment_link function in Template.pm in Bugzilla …
- CVE-2012-1970Multiple unspecified vulnerabilities in the browser engine i…
- CVE-2012-1972Use-after-free vulnerability in the nsHTMLEditor::CollapseAd…
- CVE-2012-1973Use-after-free vulnerability in the nsObjectLoadingContent::…
- CVE-2012-1974Use-after-free vulnerability in the gfxTextRun::CanBreakLine…
- CVE-2012-1975Use-after-free vulnerability in the PresShell::CompleteMove …
- CVE-2012-1976Use-after-free vulnerability in the nsHTMLSelectElement::Sub…
- CVE-2012-1977WellinTech KingSCADA 3.0 uses a cleartext base64 format for …
Are you affected by CVE-2012-1971?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
