| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2013-0744 |
Use-after-free vulnerability in the TableBackgroundPainter::TableBackgroundData::Destroy function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an HTML document with a table containing many columns and column groups. Published: January 13, 2013; 3:55:01 PM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2012-5144 |
Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via vectors related to "an off-by-one overwrite when switching to LTP profile from MAIN." Published: December 12, 2012; 6:38:44 AM -0500 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2012-5143 |
Integer overflow in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to PPAPI image buffers. Published: December 12, 2012; 6:38:44 AM -0500 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2012-5142 |
Google Chrome before 23.0.1271.97 does not properly handle history navigation, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors. Published: December 12, 2012; 6:38:44 AM -0500 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2012-5141 |
Google Chrome before 23.0.1271.97 does not properly restrict instantiation of the Chromoting client plug-in, which has unspecified impact and attack vectors. Published: December 12, 2012; 6:38:44 AM -0500 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2012-5140 |
Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the URL loader. Published: December 12, 2012; 6:38:44 AM -0500 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2012-5139 |
Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to visibility events. Published: December 12, 2012; 6:38:44 AM -0500 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2012-5138 |
Google Chrome before 23.0.1271.95 does not properly handle file paths, which has unspecified impact and attack vectors. Published: December 04, 2012; 1:05:55 AM -0500 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2012-5137 |
Use-after-free vulnerability in Google Chrome before 23.0.1271.95 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the Media Source API. Published: December 04, 2012; 1:05:55 AM -0500 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-2012-5136 |
Google Chrome before 23.0.1271.91 does not properly perform a cast of an unspecified variable during handling of the INPUT element, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted HTML document. Published: November 27, 2012; 8:55:01 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2012-5135 |
Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing. Published: November 27, 2012; 8:55:01 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2012-5133 |
Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG filters. Published: November 27, 2012; 8:55:01 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2012-5132 |
Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application crash) via a response with chunked transfer coding. Published: November 27, 2012; 8:55:01 PM -0500 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2012-5130 |
Skia, as used in Google Chrome before 23.0.1271.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. Published: November 27, 2012; 8:55:00 PM -0500 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2012-3515 |
Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space." Published: November 23, 2012; 3:55:03 PM -0500 |
V3.x:(not available) V2.0: 7.2 HIGH |
| CVE-2012-5843 |
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Published: November 21, 2012; 7:55:03 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2012-5842 |
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Published: November 21, 2012; 7:55:03 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2012-5841 |
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 implement cross-origin wrappers with a filtering behavior that does not properly restrict write actions, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site. Published: November 21, 2012; 7:55:03 AM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2012-5840 |
Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-4214. Published: November 21, 2012; 7:55:03 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2012-5839 |
Heap-based buffer overflow in the gfxShapedWord::CompressedGlyph::IsClusterStart function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via unspecified vectors. Published: November 21, 2012; 7:55:03 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |