CVE-2012-3967

CVSS v2.0 9.3 (High)
93% Progress
EPSS 0.89 % (83th)
0.89% Progress
Affected Products 15
Advisories 8

The WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 on Linux, when a large number of sampler uniforms are used, does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a crafted web site.

Weaknesses
CWE-787
Out-of-bounds Write
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2012-08-29 10:56:40
(12 years ago)
Updated Date
2020-08-14 17:21:26
(4 years ago)

Affected Products

Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Mozilla Firefox prior 15.0 version cpe:2.3:a:mozilla:firefox < 15.0
OR  
  Running on/with
  Mozilla Firefox Esr from 10.0 version and prior 10.0.7 version cpe:2.3:a:mozilla:firefox_esr >= 10.0 < 10.0.7
OR  
  Running on/with
  Mozilla Seamonkey prior 2.12 version cpe:2.3:a:mozilla:seamonkey < 2.12
OR  
  Running on/with
  Mozilla Thunderbird prior 15.0 version cpe:2.3:a:mozilla:thunderbird < 15.0
OR  
  Running on/with
  Mozilla Thunderbird Esr from 10.0 version and prior 10.0.7 version cpe:2.3:a:mozilla:thunderbird_esr >= 10.0 < 10.0.7
OR  
  Running on/with
  Linux Kernel cpe:2.3:o:linux:linux_kernel

Configuration #2

AND
    CPE23 From Up To
OR  
  Opensuse 12.2 cpe:2.3:o:opensuse:opensuse:12.2
OR  
  Running on/with
  Suse Linux Enterprise Desktop 10 SP4 cpe:2.3:o:suse:linux_enterprise_desktop:10:sp4
OR  
  Running on/with
  Suse Linux Enterprise Desktop 11 SP2 cpe:2.3:o:suse:linux_enterprise_desktop:11:sp2
OR  
  Running on/with
  Suse Linux Enterprise Server 10 SP4 cpe:2.3:o:suse:linux_enterprise_server:10:sp4
OR  
  Running on/with
  Suse Linux Enterprise Server 11 SP2 cpe:2.3:o:suse:linux_enterprise_server:11:sp2
OR  
  Running on/with
  Suse Linux Enterprise Server 11 SP2 for Vmware cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:vmware
OR  
  Running on/with
  Suse Linux Enterprise Software Development Kit 10 SP4 cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp4
OR  
  Running on/with
  Suse Linux Enterprise Software Development Kit 11 SP2 cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp2

Configuration #3

AND
    CPE23 From Up To
OR  
  Redhat Enterprise Linux Desktop 5.0 cpe:2.3:o:redhat:enterprise_linux_desktop:5.0
OR  
  Running on/with
  Redhat Enterprise Linux Desktop 6.0 cpe:2.3:o:redhat:enterprise_linux_desktop:6.0
OR  
  Running on/with
  Redhat Enterprise Linux Eus 6.3 cpe:2.3:o:redhat:enterprise_linux_eus:6.3
OR  
  Running on/with
  Redhat Enterprise Linux Server 5.0 cpe:2.3:o:redhat:enterprise_linux_server:5.0
OR  
  Running on/with
  Redhat Enterprise Linux Server 6.0 cpe:2.3:o:redhat:enterprise_linux_server:6.0
OR  
  Running on/with
  Redhat Enterprise Linux Workstation 5.0 cpe:2.3:o:redhat:enterprise_linux_workstation:5.0
OR  
  Running on/with
  Redhat Enterprise Linux Workstation 6.0 cpe:2.3:o:redhat:enterprise_linux_workstation:6.0

Configuration #4

AND
    CPE23 From Up To
OR  
  Canonical Ubuntu Linux 10.04 cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-
OR  
  Running on/with
  Canonical Ubuntu Linux 11.04 cpe:2.3:o:canonical:ubuntu_linux:11.04
OR  
  Running on/with
  Canonical Ubuntu Linux 11.10 cpe:2.3:o:canonical:ubuntu_linux:11.10
OR  
  Running on/with
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...