| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2012-4564 |
ppm2tiff does not check the return value of the TIFFScanlineSize function, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PPM image that triggers an integer overflow, a zero-memory allocation, and a heap-based buffer overflow. Published: November 11, 2012; 8:00:58 AM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2012-4540 |
Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.x before 1.4.1 allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly execute arbitrary code via a crafted webpage that triggers a heap-based buffer overflow, related to an error message and a "triggering event attached to applet." NOTE: the 1.4.x versions were originally associated with CVE-2013-4349, but that entry has been MERGED with this one. Published: November 11, 2012; 8:00:54 AM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2012-4196 |
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object. Published: October 29, 2012; 2:55:01 PM -0400 |
V3.x:(not available) V2.0: 6.4 MEDIUM |
| CVE-2012-4195 |
The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 does not properly determine the calling document and principal in its return value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site, and makes it easier for remote attackers to execute arbitrary JavaScript code by leveraging certain add-on behavior. Published: October 29, 2012; 2:55:01 PM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2012-4194 |
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 do not prevent use of the valueOf method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin. Published: October 29, 2012; 2:55:01 PM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2012-4183 |
Use-after-free vulnerability in the DOMSVGTests::GetRequiredFeatures function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors. Published: October 10, 2012; 1:55:02 PM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2012-2888 |
Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG text references. Published: September 26, 2012; 6:56:04 AM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2012-2887 |
Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving onclick events. Published: September 26, 2012; 6:56:04 AM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2012-2886 |
Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Google V8 bindings, aka "Universal XSS (UXSS)." Published: September 26, 2012; 6:56:04 AM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2012-2885 |
Double free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to application exit. Published: September 26, 2012; 6:56:04 AM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2012-2884 |
Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. Published: September 26, 2012; 6:56:04 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2012-2883 |
Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vulnerability than CVE-2012-2874. Published: September 26, 2012; 6:56:04 AM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2012-2882 |
FFmpeg, as used in Google Chrome before 22.0.1229.79, does not properly handle OGG containers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, related to a "wild pointer" issue. Published: September 26, 2012; 6:56:04 AM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2012-2881 |
Google Chrome before 22.0.1229.79 does not properly handle plug-ins, which allows remote attackers to cause a denial of service (DOM tree corruption) or possibly have unspecified other impact via unknown vectors. Published: September 26, 2012; 6:56:04 AM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2012-2880 |
Race condition in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the plug-in paint buffer. Published: September 26, 2012; 6:56:04 AM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2012-2879 |
Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service (DOM topology corruption) via a crafted document. Published: September 26, 2012; 6:56:04 AM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2012-2878 |
Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to plug-in handling. Published: September 26, 2012; 6:56:04 AM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2012-2877 |
The extension system in Google Chrome before 22.0.1229.79 does not properly handle modal dialogs, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors. Published: September 26, 2012; 6:56:04 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2012-2876 |
Buffer overflow in the SSE2 optimization functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. Published: September 26, 2012; 6:56:04 AM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-2012-2874 |
Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vulnerability than CVE-2012-2883. Published: September 26, 2012; 6:56:04 AM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |