{"cves":[{"id":"CVE-2012-5248","published":"2012-10-09T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before\n11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before\n11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and\nbefore 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe\nAIR SDK before 3.4.0.2710 allows attackers to execute arbitrary code via\nunspecified vectors, a different vulnerability than other Flash Player\nbuffer overflow CVEs listed in APSB12-22.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.adobe.com/support/security/bulletins/apsb12-22.html","https://www.cve.org/CVERecord?id=CVE-2012-5248"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"11.2.202.243-0lucid1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"11.2.202.243-0natty1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"11.2.202.243-0oneiric1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.243-0precise1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.243","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"11.2.202.243ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"11.2.202.243ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"11.2.202.243ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.243ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.243","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-5111","published":"2012-10-09T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 22.0.1229.92 does not monitor for crashes of Pepper\nplug-ins, which has unspecified impact and remote attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/chromium/issues/detail?id=151895","http://googlechromereleases.blogspot.com/2012/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2012-5111"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.1271.97-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.1271.97-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.0.1271.97-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.0.1271.97-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"22.0.1229.92","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-5110","published":"2012-10-09T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe compositor in Google Chrome before 22.0.1229.92 allows remote attackers\nto cause a denial of service (out-of-bounds read) via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/chromium/issues/detail?id=151449","http://googlechromereleases.blogspot.com/2012/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2012-5110"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.1271.97-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.1271.97-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.0.1271.97-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.0.1271.97-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"22.0.1229.92","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-5109","published":"2012-10-09T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe International Components for Unicode (ICU) functionality in Google\nChrome before 22.0.1229.92 allows remote attackers to cause a denial of\nservice (out-of-bounds read) via vectors related to a regular expression.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/chromium/issues/detail?id=148692","http://googlechromereleases.blogspot.com/2012/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2012-5109"],"bugs":[""],"patches":{"chromium-browser":[],"icu":["upstream: http://bugs.icu-project.org/trac/changeset/29356"]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.1271.97-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.1271.97-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.0.1271.97-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.0.1271.97-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"22.0.1229.94~r161065-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"22.0.1229.92","component":null,"pocket":"security"}]},{"name":"icu","source":"https://ubuntu.com/security/cve?package=icu","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=icu","debian":"https://tracker.debian.org/pkg/icu","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"4.8.1.1-3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"4.8.1.1-8","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"4.8.1.1-12","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-5108","published":"2012-10-09T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRace condition in Google Chrome before 22.0.1229.92 allows remote attackers\nto execute arbitrary code via vectors related to audio devices.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/chromium/issues/detail?id=147499","http://googlechromereleases.blogspot.com/2012/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2012-5108"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.1271.97-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.1271.97-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.0.1271.97-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.0.1271.97-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"22.0.1229.92","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-2900","published":"2012-10-09T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSkia, as used in Google Chrome before 22.0.1229.92, does not properly\nrender text, which allows remote attackers to cause a denial of service\n(application crash) or possibly have unspecified other impact via unknown\nvectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/chromium/issues/detail?id=138208","http://googlechromereleases.blogspot.com/2012/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2012-2900"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.1271.97-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.1271.97-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.0.1271.97-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.0.1271.97-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"22.0.1229.92","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-4188","published":"2012-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox\nbefore 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0,\nThunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote\nattackers to execute arbitrary code via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1600-1","https://ubuntu.com/security/notices/USN-1611-1","https://www.cve.org/CVERecord?id=CVE-2012-4188"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1600-1","USN-1611-1"],"notices":[{"id":"USN-1600-1","title":"Firefox vulnerabilities","summary":"Multiple security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":[],"published":"2012-10-09T22:32:04.591059","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Firefox. If a user were\ntricked into opening a specially crafted web page, a remote attacker could\ncause Firefox to crash or potentially execute arbitrary code as the user\ninvoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,\nCVE-2012-3989)\n\nDavid Bloom and Jordi Chancel discovered that Firefox did not always\nproperly handle the <select> element. A remote attacker could exploit this\nto conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)\n\nCollin Jackson discovered that Firefox did not properly follow the HTML5\nspecification for document.domain behavior. A remote attacker could exploit\nthis to conduct cross-site scripting (XSS) attacks via javascript\nexecution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Firefox did not properly perform security\nchecks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page, a remote attacker could exploit this to execute arbitrary\ncode as the user invoking the program. (CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Firefox. A remote\nattacker could exploit this to spoof the location property to inject script\nor intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Firefox that allowed\na remote attacker to conduct cross-site scripting (XSS) attacks.\n(CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nFirefox when using the Address Sanitizer tool. If a user were tricked into\nopening a specially crafted web page, a remote attacker could cause Firefox\nto crash or potentially execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3983","CVE-2012-3982","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3991","CVE-2012-3994","CVE-2012-3993","CVE-2012-4184","CVE-2012-3992","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-3990"]},{"id":"USN-1611-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1062587","https://launchpad.net/bugs/1065292"],"published":"2012-10-12T18:37:42.121496","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Thunderbird. If a user were\ntricked into opening a malicious website and had JavaScript enabled, an\nattacker could exploit these to execute arbitrary JavaScript code within\nthe context of another website or arbitrary code as the user invoking the\nprogram. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,\nCVE-2012-4191)\n\nDavid Bloom and Jordi Chancel discovered that Thunderbird did not always\nproperly handle the <select> element. If a user were tricked into opening a\nmalicious website and had JavaScript enabled, a remote attacker could\nexploit this to conduct URL spoofing and clickjacking attacks.\n(CVE-2012-3984)\n\nCollin Jackson discovered that Thunderbird did not properly follow the\nHTML5 specification for document.domain behavior. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, a remote\nattacker could exploit this to conduct cross-site scripting (XSS) attacks\nvia JavaScript execution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Thunderbird did not properly perform\nsecurity checks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page and had JavaScript enabled, a remote attacker could\nexploit this to execute arbitrary code as the user invoking the program.\n(CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Thunderbird. If a user\nwere tricked into opening a malicious website and had JavaScript enabled, a\nremote attacker could exploit this to spoof the location property to inject\nscript or intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Thunderbird that\nallowed a remote attacker to conduct cross-site scripting (XSS) attacks.\nWith cross-site scripting vulnerabilities, if a user were tricked into\nviewing a specially crafted page and had JavaScript enabled, a remote\nattacker could exploit these to modify the contents, or steal confidential\ndata, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nThunderbird when using the Address Sanitizer tool. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, an attacker\ncould exploit these to execute arbitrary JavaScript code within the context\nof another website or execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n\nIt was discovered that Thunderbird allowed improper access to the Location\nobject. An attacker could exploit this to obtain sensitive information.\nUnder certain circumstances, a remote attacker could use this vulnerability\nto potentially execute arbitrary code as the user invoking the program.\n(CVE-2012-4192, CVE-2012-4193)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3982","CVE-2012-3983","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3990","CVE-2012-3991","CVE-2012-3992","CVE-2012-3993","CVE-2012-3994","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4184","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-4191","CVE-2012-4192","CVE-2012-4193"]}]},{"id":"CVE-2012-4187","published":"2012-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird\nbefore 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13\ndo not properly manage a certain insPos variable, which allows remote\nattackers to execute arbitrary code or cause a denial of service (heap\nmemory corruption and assertion failure) via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1600-1","https://ubuntu.com/security/notices/USN-1611-1","https://www.cve.org/CVERecord?id=CVE-2012-4187"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1600-1","USN-1611-1"],"notices":[{"id":"USN-1600-1","title":"Firefox vulnerabilities","summary":"Multiple security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":[],"published":"2012-10-09T22:32:04.591059","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Firefox. If a user were\ntricked into opening a specially crafted web page, a remote attacker could\ncause Firefox to crash or potentially execute arbitrary code as the user\ninvoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,\nCVE-2012-3989)\n\nDavid Bloom and Jordi Chancel discovered that Firefox did not always\nproperly handle the <select> element. A remote attacker could exploit this\nto conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)\n\nCollin Jackson discovered that Firefox did not properly follow the HTML5\nspecification for document.domain behavior. A remote attacker could exploit\nthis to conduct cross-site scripting (XSS) attacks via javascript\nexecution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Firefox did not properly perform security\nchecks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page, a remote attacker could exploit this to execute arbitrary\ncode as the user invoking the program. (CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Firefox. A remote\nattacker could exploit this to spoof the location property to inject script\nor intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Firefox that allowed\na remote attacker to conduct cross-site scripting (XSS) attacks.\n(CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nFirefox when using the Address Sanitizer tool. If a user were tricked into\nopening a specially crafted web page, a remote attacker could cause Firefox\nto crash or potentially execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3983","CVE-2012-3982","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3991","CVE-2012-3994","CVE-2012-3993","CVE-2012-4184","CVE-2012-3992","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-3990"]},{"id":"USN-1611-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1062587","https://launchpad.net/bugs/1065292"],"published":"2012-10-12T18:37:42.121496","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Thunderbird. If a user were\ntricked into opening a malicious website and had JavaScript enabled, an\nattacker could exploit these to execute arbitrary JavaScript code within\nthe context of another website or arbitrary code as the user invoking the\nprogram. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,\nCVE-2012-4191)\n\nDavid Bloom and Jordi Chancel discovered that Thunderbird did not always\nproperly handle the <select> element. If a user were tricked into opening a\nmalicious website and had JavaScript enabled, a remote attacker could\nexploit this to conduct URL spoofing and clickjacking attacks.\n(CVE-2012-3984)\n\nCollin Jackson discovered that Thunderbird did not properly follow the\nHTML5 specification for document.domain behavior. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, a remote\nattacker could exploit this to conduct cross-site scripting (XSS) attacks\nvia JavaScript execution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Thunderbird did not properly perform\nsecurity checks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page and had JavaScript enabled, a remote attacker could\nexploit this to execute arbitrary code as the user invoking the program.\n(CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Thunderbird. If a user\nwere tricked into opening a malicious website and had JavaScript enabled, a\nremote attacker could exploit this to spoof the location property to inject\nscript or intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Thunderbird that\nallowed a remote attacker to conduct cross-site scripting (XSS) attacks.\nWith cross-site scripting vulnerabilities, if a user were tricked into\nviewing a specially crafted page and had JavaScript enabled, a remote\nattacker could exploit these to modify the contents, or steal confidential\ndata, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nThunderbird when using the Address Sanitizer tool. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, an attacker\ncould exploit these to execute arbitrary JavaScript code within the context\nof another website or execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n\nIt was discovered that Thunderbird allowed improper access to the Location\nobject. An attacker could exploit this to obtain sensitive information.\nUnder certain circumstances, a remote attacker could use this vulnerability\nto potentially execute arbitrary code as the user invoking the program.\n(CVE-2012-4192, CVE-2012-4193)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3982","CVE-2012-3983","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3990","CVE-2012-3991","CVE-2012-3992","CVE-2012-3993","CVE-2012-3994","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4184","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-4191","CVE-2012-4192","CVE-2012-4193"]}]},{"id":"CVE-2012-4186","published":"2012-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the nsWaveReader::DecodeAudioData function in\nMozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird\nbefore 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13\nallows remote attackers to execute arbitrary code via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1600-1","https://ubuntu.com/security/notices/USN-1611-1","https://www.cve.org/CVERecord?id=CVE-2012-4186"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1600-1","USN-1611-1"],"notices":[{"id":"USN-1600-1","title":"Firefox vulnerabilities","summary":"Multiple security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":[],"published":"2012-10-09T22:32:04.591059","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Firefox. If a user were\ntricked into opening a specially crafted web page, a remote attacker could\ncause Firefox to crash or potentially execute arbitrary code as the user\ninvoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,\nCVE-2012-3989)\n\nDavid Bloom and Jordi Chancel discovered that Firefox did not always\nproperly handle the <select> element. A remote attacker could exploit this\nto conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)\n\nCollin Jackson discovered that Firefox did not properly follow the HTML5\nspecification for document.domain behavior. A remote attacker could exploit\nthis to conduct cross-site scripting (XSS) attacks via javascript\nexecution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Firefox did not properly perform security\nchecks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page, a remote attacker could exploit this to execute arbitrary\ncode as the user invoking the program. (CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Firefox. A remote\nattacker could exploit this to spoof the location property to inject script\nor intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Firefox that allowed\na remote attacker to conduct cross-site scripting (XSS) attacks.\n(CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nFirefox when using the Address Sanitizer tool. If a user were tricked into\nopening a specially crafted web page, a remote attacker could cause Firefox\nto crash or potentially execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3983","CVE-2012-3982","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3991","CVE-2012-3994","CVE-2012-3993","CVE-2012-4184","CVE-2012-3992","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-3990"]},{"id":"USN-1611-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1062587","https://launchpad.net/bugs/1065292"],"published":"2012-10-12T18:37:42.121496","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Thunderbird. If a user were\ntricked into opening a malicious website and had JavaScript enabled, an\nattacker could exploit these to execute arbitrary JavaScript code within\nthe context of another website or arbitrary code as the user invoking the\nprogram. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,\nCVE-2012-4191)\n\nDavid Bloom and Jordi Chancel discovered that Thunderbird did not always\nproperly handle the <select> element. If a user were tricked into opening a\nmalicious website and had JavaScript enabled, a remote attacker could\nexploit this to conduct URL spoofing and clickjacking attacks.\n(CVE-2012-3984)\n\nCollin Jackson discovered that Thunderbird did not properly follow the\nHTML5 specification for document.domain behavior. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, a remote\nattacker could exploit this to conduct cross-site scripting (XSS) attacks\nvia JavaScript execution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Thunderbird did not properly perform\nsecurity checks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page and had JavaScript enabled, a remote attacker could\nexploit this to execute arbitrary code as the user invoking the program.\n(CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Thunderbird. If a user\nwere tricked into opening a malicious website and had JavaScript enabled, a\nremote attacker could exploit this to spoof the location property to inject\nscript or intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Thunderbird that\nallowed a remote attacker to conduct cross-site scripting (XSS) attacks.\nWith cross-site scripting vulnerabilities, if a user were tricked into\nviewing a specially crafted page and had JavaScript enabled, a remote\nattacker could exploit these to modify the contents, or steal confidential\ndata, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nThunderbird when using the Address Sanitizer tool. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, an attacker\ncould exploit these to execute arbitrary JavaScript code within the context\nof another website or execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n\nIt was discovered that Thunderbird allowed improper access to the Location\nobject. An attacker could exploit this to obtain sensitive information.\nUnder certain circumstances, a remote attacker could use this vulnerability\nto potentially execute arbitrary code as the user invoking the program.\n(CVE-2012-4192, CVE-2012-4193)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3982","CVE-2012-3983","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3990","CVE-2012-3991","CVE-2012-3992","CVE-2012-3993","CVE-2012-3994","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4184","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-4191","CVE-2012-4192","CVE-2012-4193"]}]},{"id":"CVE-2012-4185","published":"2012-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the nsCharTraits::length function in Mozilla Firefox\nbefore 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0,\nThunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote\nattackers to execute arbitrary code or cause a denial of service (heap\nmemory corruption) via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1600-1","https://ubuntu.com/security/notices/USN-1611-1","https://www.cve.org/CVERecord?id=CVE-2012-4185"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1600-1","USN-1611-1"],"notices":[{"id":"USN-1600-1","title":"Firefox vulnerabilities","summary":"Multiple security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":[],"published":"2012-10-09T22:32:04.591059","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Firefox. If a user were\ntricked into opening a specially crafted web page, a remote attacker could\ncause Firefox to crash or potentially execute arbitrary code as the user\ninvoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,\nCVE-2012-3989)\n\nDavid Bloom and Jordi Chancel discovered that Firefox did not always\nproperly handle the <select> element. A remote attacker could exploit this\nto conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)\n\nCollin Jackson discovered that Firefox did not properly follow the HTML5\nspecification for document.domain behavior. A remote attacker could exploit\nthis to conduct cross-site scripting (XSS) attacks via javascript\nexecution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Firefox did not properly perform security\nchecks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page, a remote attacker could exploit this to execute arbitrary\ncode as the user invoking the program. (CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Firefox. A remote\nattacker could exploit this to spoof the location property to inject script\nor intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Firefox that allowed\na remote attacker to conduct cross-site scripting (XSS) attacks.\n(CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nFirefox when using the Address Sanitizer tool. If a user were tricked into\nopening a specially crafted web page, a remote attacker could cause Firefox\nto crash or potentially execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3983","CVE-2012-3982","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3991","CVE-2012-3994","CVE-2012-3993","CVE-2012-4184","CVE-2012-3992","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-3990"]},{"id":"USN-1611-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1062587","https://launchpad.net/bugs/1065292"],"published":"2012-10-12T18:37:42.121496","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Thunderbird. If a user were\ntricked into opening a malicious website and had JavaScript enabled, an\nattacker could exploit these to execute arbitrary JavaScript code within\nthe context of another website or arbitrary code as the user invoking the\nprogram. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,\nCVE-2012-4191)\n\nDavid Bloom and Jordi Chancel discovered that Thunderbird did not always\nproperly handle the <select> element. If a user were tricked into opening a\nmalicious website and had JavaScript enabled, a remote attacker could\nexploit this to conduct URL spoofing and clickjacking attacks.\n(CVE-2012-3984)\n\nCollin Jackson discovered that Thunderbird did not properly follow the\nHTML5 specification for document.domain behavior. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, a remote\nattacker could exploit this to conduct cross-site scripting (XSS) attacks\nvia JavaScript execution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Thunderbird did not properly perform\nsecurity checks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page and had JavaScript enabled, a remote attacker could\nexploit this to execute arbitrary code as the user invoking the program.\n(CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Thunderbird. If a user\nwere tricked into opening a malicious website and had JavaScript enabled, a\nremote attacker could exploit this to spoof the location property to inject\nscript or intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Thunderbird that\nallowed a remote attacker to conduct cross-site scripting (XSS) attacks.\nWith cross-site scripting vulnerabilities, if a user were tricked into\nviewing a specially crafted page and had JavaScript enabled, a remote\nattacker could exploit these to modify the contents, or steal confidential\ndata, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nThunderbird when using the Address Sanitizer tool. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, an attacker\ncould exploit these to execute arbitrary JavaScript code within the context\nof another website or execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n\nIt was discovered that Thunderbird allowed improper access to the Location\nobject. An attacker could exploit this to obtain sensitive information.\nUnder certain circumstances, a remote attacker could use this vulnerability\nto potentially execute arbitrary code as the user invoking the program.\n(CVE-2012-4192, CVE-2012-4193)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3982","CVE-2012-3983","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3990","CVE-2012-3991","CVE-2012-3992","CVE-2012-3993","CVE-2012-3994","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4184","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-4191","CVE-2012-4192","CVE-2012-4193"]}]},{"id":"CVE-2012-4184","published":"2012-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Chrome Object Wrapper (COW) implementation in Mozilla Firefox before\n16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird\nESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not prevent access\nto properties of a prototype for a standard class, which allows remote\nattackers to execute arbitrary JavaScript code with chrome privileges via a\ncrafted web site.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1600-1","https://ubuntu.com/security/notices/USN-1611-1","https://www.cve.org/CVERecord?id=CVE-2012-4184"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1600-1","USN-1611-1"],"notices":[{"id":"USN-1600-1","title":"Firefox vulnerabilities","summary":"Multiple security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":[],"published":"2012-10-09T22:32:04.591059","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Firefox. If a user were\ntricked into opening a specially crafted web page, a remote attacker could\ncause Firefox to crash or potentially execute arbitrary code as the user\ninvoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,\nCVE-2012-3989)\n\nDavid Bloom and Jordi Chancel discovered that Firefox did not always\nproperly handle the <select> element. A remote attacker could exploit this\nto conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)\n\nCollin Jackson discovered that Firefox did not properly follow the HTML5\nspecification for document.domain behavior. A remote attacker could exploit\nthis to conduct cross-site scripting (XSS) attacks via javascript\nexecution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Firefox did not properly perform security\nchecks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page, a remote attacker could exploit this to execute arbitrary\ncode as the user invoking the program. (CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Firefox. A remote\nattacker could exploit this to spoof the location property to inject script\nor intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Firefox that allowed\na remote attacker to conduct cross-site scripting (XSS) attacks.\n(CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nFirefox when using the Address Sanitizer tool. If a user were tricked into\nopening a specially crafted web page, a remote attacker could cause Firefox\nto crash or potentially execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3983","CVE-2012-3982","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3991","CVE-2012-3994","CVE-2012-3993","CVE-2012-4184","CVE-2012-3992","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-3990"]},{"id":"USN-1611-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1062587","https://launchpad.net/bugs/1065292"],"published":"2012-10-12T18:37:42.121496","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Thunderbird. If a user were\ntricked into opening a malicious website and had JavaScript enabled, an\nattacker could exploit these to execute arbitrary JavaScript code within\nthe context of another website or arbitrary code as the user invoking the\nprogram. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,\nCVE-2012-4191)\n\nDavid Bloom and Jordi Chancel discovered that Thunderbird did not always\nproperly handle the <select> element. If a user were tricked into opening a\nmalicious website and had JavaScript enabled, a remote attacker could\nexploit this to conduct URL spoofing and clickjacking attacks.\n(CVE-2012-3984)\n\nCollin Jackson discovered that Thunderbird did not properly follow the\nHTML5 specification for document.domain behavior. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, a remote\nattacker could exploit this to conduct cross-site scripting (XSS) attacks\nvia JavaScript execution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Thunderbird did not properly perform\nsecurity checks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page and had JavaScript enabled, a remote attacker could\nexploit this to execute arbitrary code as the user invoking the program.\n(CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Thunderbird. If a user\nwere tricked into opening a malicious website and had JavaScript enabled, a\nremote attacker could exploit this to spoof the location property to inject\nscript or intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Thunderbird that\nallowed a remote attacker to conduct cross-site scripting (XSS) attacks.\nWith cross-site scripting vulnerabilities, if a user were tricked into\nviewing a specially crafted page and had JavaScript enabled, a remote\nattacker could exploit these to modify the contents, or steal confidential\ndata, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nThunderbird when using the Address Sanitizer tool. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, an attacker\ncould exploit these to execute arbitrary JavaScript code within the context\nof another website or execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n\nIt was discovered that Thunderbird allowed improper access to the Location\nobject. An attacker could exploit this to obtain sensitive information.\nUnder certain circumstances, a remote attacker could use this vulnerability\nto potentially execute arbitrary code as the user invoking the program.\n(CVE-2012-4192, CVE-2012-4193)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3982","CVE-2012-3983","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3990","CVE-2012-3991","CVE-2012-3992","CVE-2012-3993","CVE-2012-3994","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4184","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-4191","CVE-2012-4192","CVE-2012-4193"]}]},{"id":"CVE-2012-4183","published":"2012-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the DOMSVGTests::GetRequiredFeatures\nfunction in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8,\nThunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey\nbefore 2.13 allows remote attackers to execute arbitrary code or cause a\ndenial of service (heap memory corruption) via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1600-1","https://ubuntu.com/security/notices/USN-1611-1","https://www.cve.org/CVERecord?id=CVE-2012-4183"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1600-1","USN-1611-1"],"notices":[{"id":"USN-1600-1","title":"Firefox vulnerabilities","summary":"Multiple security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":[],"published":"2012-10-09T22:32:04.591059","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Firefox. If a user were\ntricked into opening a specially crafted web page, a remote attacker could\ncause Firefox to crash or potentially execute arbitrary code as the user\ninvoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,\nCVE-2012-3989)\n\nDavid Bloom and Jordi Chancel discovered that Firefox did not always\nproperly handle the <select> element. A remote attacker could exploit this\nto conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)\n\nCollin Jackson discovered that Firefox did not properly follow the HTML5\nspecification for document.domain behavior. A remote attacker could exploit\nthis to conduct cross-site scripting (XSS) attacks via javascript\nexecution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Firefox did not properly perform security\nchecks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page, a remote attacker could exploit this to execute arbitrary\ncode as the user invoking the program. (CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Firefox. A remote\nattacker could exploit this to spoof the location property to inject script\nor intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Firefox that allowed\na remote attacker to conduct cross-site scripting (XSS) attacks.\n(CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nFirefox when using the Address Sanitizer tool. If a user were tricked into\nopening a specially crafted web page, a remote attacker could cause Firefox\nto crash or potentially execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3983","CVE-2012-3982","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3991","CVE-2012-3994","CVE-2012-3993","CVE-2012-4184","CVE-2012-3992","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-3990"]},{"id":"USN-1611-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1062587","https://launchpad.net/bugs/1065292"],"published":"2012-10-12T18:37:42.121496","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Thunderbird. If a user were\ntricked into opening a malicious website and had JavaScript enabled, an\nattacker could exploit these to execute arbitrary JavaScript code within\nthe context of another website or arbitrary code as the user invoking the\nprogram. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,\nCVE-2012-4191)\n\nDavid Bloom and Jordi Chancel discovered that Thunderbird did not always\nproperly handle the <select> element. If a user were tricked into opening a\nmalicious website and had JavaScript enabled, a remote attacker could\nexploit this to conduct URL spoofing and clickjacking attacks.\n(CVE-2012-3984)\n\nCollin Jackson discovered that Thunderbird did not properly follow the\nHTML5 specification for document.domain behavior. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, a remote\nattacker could exploit this to conduct cross-site scripting (XSS) attacks\nvia JavaScript execution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Thunderbird did not properly perform\nsecurity checks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page and had JavaScript enabled, a remote attacker could\nexploit this to execute arbitrary code as the user invoking the program.\n(CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Thunderbird. If a user\nwere tricked into opening a malicious website and had JavaScript enabled, a\nremote attacker could exploit this to spoof the location property to inject\nscript or intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Thunderbird that\nallowed a remote attacker to conduct cross-site scripting (XSS) attacks.\nWith cross-site scripting vulnerabilities, if a user were tricked into\nviewing a specially crafted page and had JavaScript enabled, a remote\nattacker could exploit these to modify the contents, or steal confidential\ndata, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nThunderbird when using the Address Sanitizer tool. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, an attacker\ncould exploit these to execute arbitrary JavaScript code within the context\nof another website or execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n\nIt was discovered that Thunderbird allowed improper access to the Location\nobject. An attacker could exploit this to obtain sensitive information.\nUnder certain circumstances, a remote attacker could use this vulnerability\nto potentially execute arbitrary code as the user invoking the program.\n(CVE-2012-4192, CVE-2012-4193)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3982","CVE-2012-3983","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3990","CVE-2012-3991","CVE-2012-3992","CVE-2012-3993","CVE-2012-3994","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4184","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-4191","CVE-2012-4192","CVE-2012-4193"]}]},{"id":"CVE-2012-4182","published":"2012-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the nsTextEditRules::WillInsert function in\nMozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird\nbefore 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13\nallows remote attackers to execute arbitrary code or cause a denial of\nservice (heap memory corruption) via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1600-1","https://ubuntu.com/security/notices/USN-1611-1","https://www.cve.org/CVERecord?id=CVE-2012-4182"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1600-1","USN-1611-1"],"notices":[{"id":"USN-1600-1","title":"Firefox vulnerabilities","summary":"Multiple security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":[],"published":"2012-10-09T22:32:04.591059","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Firefox. If a user were\ntricked into opening a specially crafted web page, a remote attacker could\ncause Firefox to crash or potentially execute arbitrary code as the user\ninvoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,\nCVE-2012-3989)\n\nDavid Bloom and Jordi Chancel discovered that Firefox did not always\nproperly handle the <select> element. A remote attacker could exploit this\nto conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)\n\nCollin Jackson discovered that Firefox did not properly follow the HTML5\nspecification for document.domain behavior. A remote attacker could exploit\nthis to conduct cross-site scripting (XSS) attacks via javascript\nexecution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Firefox did not properly perform security\nchecks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page, a remote attacker could exploit this to execute arbitrary\ncode as the user invoking the program. (CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Firefox. A remote\nattacker could exploit this to spoof the location property to inject script\nor intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Firefox that allowed\na remote attacker to conduct cross-site scripting (XSS) attacks.\n(CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nFirefox when using the Address Sanitizer tool. If a user were tricked into\nopening a specially crafted web page, a remote attacker could cause Firefox\nto crash or potentially execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3983","CVE-2012-3982","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3991","CVE-2012-3994","CVE-2012-3993","CVE-2012-4184","CVE-2012-3992","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-3990"]},{"id":"USN-1611-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1062587","https://launchpad.net/bugs/1065292"],"published":"2012-10-12T18:37:42.121496","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Thunderbird. If a user were\ntricked into opening a malicious website and had JavaScript enabled, an\nattacker could exploit these to execute arbitrary JavaScript code within\nthe context of another website or arbitrary code as the user invoking the\nprogram. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,\nCVE-2012-4191)\n\nDavid Bloom and Jordi Chancel discovered that Thunderbird did not always\nproperly handle the <select> element. If a user were tricked into opening a\nmalicious website and had JavaScript enabled, a remote attacker could\nexploit this to conduct URL spoofing and clickjacking attacks.\n(CVE-2012-3984)\n\nCollin Jackson discovered that Thunderbird did not properly follow the\nHTML5 specification for document.domain behavior. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, a remote\nattacker could exploit this to conduct cross-site scripting (XSS) attacks\nvia JavaScript execution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Thunderbird did not properly perform\nsecurity checks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page and had JavaScript enabled, a remote attacker could\nexploit this to execute arbitrary code as the user invoking the program.\n(CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Thunderbird. If a user\nwere tricked into opening a malicious website and had JavaScript enabled, a\nremote attacker could exploit this to spoof the location property to inject\nscript or intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Thunderbird that\nallowed a remote attacker to conduct cross-site scripting (XSS) attacks.\nWith cross-site scripting vulnerabilities, if a user were tricked into\nviewing a specially crafted page and had JavaScript enabled, a remote\nattacker could exploit these to modify the contents, or steal confidential\ndata, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nThunderbird when using the Address Sanitizer tool. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, an attacker\ncould exploit these to execute arbitrary JavaScript code within the context\nof another website or execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n\nIt was discovered that Thunderbird allowed improper access to the Location\nobject. An attacker could exploit this to obtain sensitive information.\nUnder certain circumstances, a remote attacker could use this vulnerability\nto potentially execute arbitrary code as the user invoking the program.\n(CVE-2012-4192, CVE-2012-4193)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3982","CVE-2012-3983","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3990","CVE-2012-3991","CVE-2012-3992","CVE-2012-3993","CVE-2012-3994","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4184","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-4191","CVE-2012-4192","CVE-2012-4193"]}]},{"id":"CVE-2012-4181","published":"2012-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the nsSMILAnimationController::DoSample\nfunction in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8,\nThunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey\nbefore 2.13 allows remote attackers to execute arbitrary code or cause a\ndenial of service (heap memory corruption) via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1600-1","https://ubuntu.com/security/notices/USN-1611-1","https://www.cve.org/CVERecord?id=CVE-2012-4181"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1600-1","USN-1611-1"],"notices":[{"id":"USN-1600-1","title":"Firefox vulnerabilities","summary":"Multiple security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":[],"published":"2012-10-09T22:32:04.591059","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Firefox. If a user were\ntricked into opening a specially crafted web page, a remote attacker could\ncause Firefox to crash or potentially execute arbitrary code as the user\ninvoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,\nCVE-2012-3989)\n\nDavid Bloom and Jordi Chancel discovered that Firefox did not always\nproperly handle the <select> element. A remote attacker could exploit this\nto conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)\n\nCollin Jackson discovered that Firefox did not properly follow the HTML5\nspecification for document.domain behavior. A remote attacker could exploit\nthis to conduct cross-site scripting (XSS) attacks via javascript\nexecution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Firefox did not properly perform security\nchecks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page, a remote attacker could exploit this to execute arbitrary\ncode as the user invoking the program. (CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Firefox. A remote\nattacker could exploit this to spoof the location property to inject script\nor intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Firefox that allowed\na remote attacker to conduct cross-site scripting (XSS) attacks.\n(CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nFirefox when using the Address Sanitizer tool. If a user were tricked into\nopening a specially crafted web page, a remote attacker could cause Firefox\nto crash or potentially execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3983","CVE-2012-3982","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3991","CVE-2012-3994","CVE-2012-3993","CVE-2012-4184","CVE-2012-3992","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-3990"]},{"id":"USN-1611-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1062587","https://launchpad.net/bugs/1065292"],"published":"2012-10-12T18:37:42.121496","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Thunderbird. If a user were\ntricked into opening a malicious website and had JavaScript enabled, an\nattacker could exploit these to execute arbitrary JavaScript code within\nthe context of another website or arbitrary code as the user invoking the\nprogram. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,\nCVE-2012-4191)\n\nDavid Bloom and Jordi Chancel discovered that Thunderbird did not always\nproperly handle the <select> element. If a user were tricked into opening a\nmalicious website and had JavaScript enabled, a remote attacker could\nexploit this to conduct URL spoofing and clickjacking attacks.\n(CVE-2012-3984)\n\nCollin Jackson discovered that Thunderbird did not properly follow the\nHTML5 specification for document.domain behavior. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, a remote\nattacker could exploit this to conduct cross-site scripting (XSS) attacks\nvia JavaScript execution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Thunderbird did not properly perform\nsecurity checks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page and had JavaScript enabled, a remote attacker could\nexploit this to execute arbitrary code as the user invoking the program.\n(CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Thunderbird. If a user\nwere tricked into opening a malicious website and had JavaScript enabled, a\nremote attacker could exploit this to spoof the location property to inject\nscript or intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Thunderbird that\nallowed a remote attacker to conduct cross-site scripting (XSS) attacks.\nWith cross-site scripting vulnerabilities, if a user were tricked into\nviewing a specially crafted page and had JavaScript enabled, a remote\nattacker could exploit these to modify the contents, or steal confidential\ndata, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nThunderbird when using the Address Sanitizer tool. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, an attacker\ncould exploit these to execute arbitrary JavaScript code within the context\nof another website or execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n\nIt was discovered that Thunderbird allowed improper access to the Location\nobject. An attacker could exploit this to obtain sensitive information.\nUnder certain circumstances, a remote attacker could use this vulnerability\nto potentially execute arbitrary code as the user invoking the program.\n(CVE-2012-4192, CVE-2012-4193)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3982","CVE-2012-3983","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3990","CVE-2012-3991","CVE-2012-3992","CVE-2012-3993","CVE-2012-3994","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4184","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-4191","CVE-2012-4192","CVE-2012-4193"]}]},{"id":"CVE-2012-4180","published":"2012-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the nsHTMLEditor::IsPrevCharInNodeWhitespace\nfunction in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8,\nThunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey\nbefore 2.13 allows remote attackers to execute arbitrary code via\nunspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1600-1","https://ubuntu.com/security/notices/USN-1611-1","https://www.cve.org/CVERecord?id=CVE-2012-4180"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1600-1","USN-1611-1"],"notices":[{"id":"USN-1600-1","title":"Firefox vulnerabilities","summary":"Multiple security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":[],"published":"2012-10-09T22:32:04.591059","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Firefox. If a user were\ntricked into opening a specially crafted web page, a remote attacker could\ncause Firefox to crash or potentially execute arbitrary code as the user\ninvoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,\nCVE-2012-3989)\n\nDavid Bloom and Jordi Chancel discovered that Firefox did not always\nproperly handle the <select> element. A remote attacker could exploit this\nto conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)\n\nCollin Jackson discovered that Firefox did not properly follow the HTML5\nspecification for document.domain behavior. A remote attacker could exploit\nthis to conduct cross-site scripting (XSS) attacks via javascript\nexecution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Firefox did not properly perform security\nchecks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page, a remote attacker could exploit this to execute arbitrary\ncode as the user invoking the program. (CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Firefox. A remote\nattacker could exploit this to spoof the location property to inject script\nor intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Firefox that allowed\na remote attacker to conduct cross-site scripting (XSS) attacks.\n(CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nFirefox when using the Address Sanitizer tool. If a user were tricked into\nopening a specially crafted web page, a remote attacker could cause Firefox\nto crash or potentially execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3983","CVE-2012-3982","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3991","CVE-2012-3994","CVE-2012-3993","CVE-2012-4184","CVE-2012-3992","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-3990"]},{"id":"USN-1611-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1062587","https://launchpad.net/bugs/1065292"],"published":"2012-10-12T18:37:42.121496","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Thunderbird. If a user were\ntricked into opening a malicious website and had JavaScript enabled, an\nattacker could exploit these to execute arbitrary JavaScript code within\nthe context of another website or arbitrary code as the user invoking the\nprogram. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,\nCVE-2012-4191)\n\nDavid Bloom and Jordi Chancel discovered that Thunderbird did not always\nproperly handle the <select> element. If a user were tricked into opening a\nmalicious website and had JavaScript enabled, a remote attacker could\nexploit this to conduct URL spoofing and clickjacking attacks.\n(CVE-2012-3984)\n\nCollin Jackson discovered that Thunderbird did not properly follow the\nHTML5 specification for document.domain behavior. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, a remote\nattacker could exploit this to conduct cross-site scripting (XSS) attacks\nvia JavaScript execution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Thunderbird did not properly perform\nsecurity checks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page and had JavaScript enabled, a remote attacker could\nexploit this to execute arbitrary code as the user invoking the program.\n(CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Thunderbird. If a user\nwere tricked into opening a malicious website and had JavaScript enabled, a\nremote attacker could exploit this to spoof the location property to inject\nscript or intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Thunderbird that\nallowed a remote attacker to conduct cross-site scripting (XSS) attacks.\nWith cross-site scripting vulnerabilities, if a user were tricked into\nviewing a specially crafted page and had JavaScript enabled, a remote\nattacker could exploit these to modify the contents, or steal confidential\ndata, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nThunderbird when using the Address Sanitizer tool. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, an attacker\ncould exploit these to execute arbitrary JavaScript code within the context\nof another website or execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n\nIt was discovered that Thunderbird allowed improper access to the Location\nobject. An attacker could exploit this to obtain sensitive information.\nUnder certain circumstances, a remote attacker could use this vulnerability\nto potentially execute arbitrary code as the user invoking the program.\n(CVE-2012-4192, CVE-2012-4193)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3982","CVE-2012-3983","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3990","CVE-2012-3991","CVE-2012-3992","CVE-2012-3993","CVE-2012-3994","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4184","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-4191","CVE-2012-4192","CVE-2012-4193"]}]},{"id":"CVE-2012-4179","published":"2012-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the nsHTMLCSSUtils::CreateCSSPropertyTxn\nfunction in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8,\nThunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey\nbefore 2.13 allows remote attackers to execute arbitrary code or cause a\ndenial of service (heap memory corruption) via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1600-1","https://ubuntu.com/security/notices/USN-1611-1","https://www.cve.org/CVERecord?id=CVE-2012-4179"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1600-1","USN-1611-1"],"notices":[{"id":"USN-1600-1","title":"Firefox vulnerabilities","summary":"Multiple security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":[],"published":"2012-10-09T22:32:04.591059","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Firefox. If a user were\ntricked into opening a specially crafted web page, a remote attacker could\ncause Firefox to crash or potentially execute arbitrary code as the user\ninvoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,\nCVE-2012-3989)\n\nDavid Bloom and Jordi Chancel discovered that Firefox did not always\nproperly handle the <select> element. A remote attacker could exploit this\nto conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)\n\nCollin Jackson discovered that Firefox did not properly follow the HTML5\nspecification for document.domain behavior. A remote attacker could exploit\nthis to conduct cross-site scripting (XSS) attacks via javascript\nexecution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Firefox did not properly perform security\nchecks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page, a remote attacker could exploit this to execute arbitrary\ncode as the user invoking the program. (CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Firefox. A remote\nattacker could exploit this to spoof the location property to inject script\nor intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Firefox that allowed\na remote attacker to conduct cross-site scripting (XSS) attacks.\n(CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nFirefox when using the Address Sanitizer tool. If a user were tricked into\nopening a specially crafted web page, a remote attacker could cause Firefox\nto crash or potentially execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3983","CVE-2012-3982","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3991","CVE-2012-3994","CVE-2012-3993","CVE-2012-4184","CVE-2012-3992","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-3990"]},{"id":"USN-1611-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1062587","https://launchpad.net/bugs/1065292"],"published":"2012-10-12T18:37:42.121496","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Thunderbird. If a user were\ntricked into opening a malicious website and had JavaScript enabled, an\nattacker could exploit these to execute arbitrary JavaScript code within\nthe context of another website or arbitrary code as the user invoking the\nprogram. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,\nCVE-2012-4191)\n\nDavid Bloom and Jordi Chancel discovered that Thunderbird did not always\nproperly handle the <select> element. If a user were tricked into opening a\nmalicious website and had JavaScript enabled, a remote attacker could\nexploit this to conduct URL spoofing and clickjacking attacks.\n(CVE-2012-3984)\n\nCollin Jackson discovered that Thunderbird did not properly follow the\nHTML5 specification for document.domain behavior. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, a remote\nattacker could exploit this to conduct cross-site scripting (XSS) attacks\nvia JavaScript execution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Thunderbird did not properly perform\nsecurity checks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page and had JavaScript enabled, a remote attacker could\nexploit this to execute arbitrary code as the user invoking the program.\n(CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Thunderbird. If a user\nwere tricked into opening a malicious website and had JavaScript enabled, a\nremote attacker could exploit this to spoof the location property to inject\nscript or intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Thunderbird that\nallowed a remote attacker to conduct cross-site scripting (XSS) attacks.\nWith cross-site scripting vulnerabilities, if a user were tricked into\nviewing a specially crafted page and had JavaScript enabled, a remote\nattacker could exploit these to modify the contents, or steal confidential\ndata, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nThunderbird when using the Address Sanitizer tool. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, an attacker\ncould exploit these to execute arbitrary JavaScript code within the context\nof another website or execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n\nIt was discovered that Thunderbird allowed improper access to the Location\nobject. An attacker could exploit this to obtain sensitive information.\nUnder certain circumstances, a remote attacker could use this vulnerability\nto potentially execute arbitrary code as the user invoking the program.\n(CVE-2012-4192, CVE-2012-4193)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3982","CVE-2012-3983","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3990","CVE-2012-3991","CVE-2012-3992","CVE-2012-3993","CVE-2012-3994","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4184","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-4191","CVE-2012-4192","CVE-2012-4193"]}]},{"id":"CVE-2012-3995","published":"2012-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe IsCSSWordSpacingSpace function in Mozilla Firefox before 16.0, Firefox\nESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x\nbefore 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute\narbitrary code or cause a denial of service (out-of-bounds read) via\nunspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1600-1","https://ubuntu.com/security/notices/USN-1611-1","https://www.cve.org/CVERecord?id=CVE-2012-3995"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1600-1","USN-1611-1"],"notices":[{"id":"USN-1600-1","title":"Firefox vulnerabilities","summary":"Multiple security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":[],"published":"2012-10-09T22:32:04.591059","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Firefox. If a user were\ntricked into opening a specially crafted web page, a remote attacker could\ncause Firefox to crash or potentially execute arbitrary code as the user\ninvoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,\nCVE-2012-3989)\n\nDavid Bloom and Jordi Chancel discovered that Firefox did not always\nproperly handle the <select> element. A remote attacker could exploit this\nto conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)\n\nCollin Jackson discovered that Firefox did not properly follow the HTML5\nspecification for document.domain behavior. A remote attacker could exploit\nthis to conduct cross-site scripting (XSS) attacks via javascript\nexecution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Firefox did not properly perform security\nchecks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page, a remote attacker could exploit this to execute arbitrary\ncode as the user invoking the program. (CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Firefox. A remote\nattacker could exploit this to spoof the location property to inject script\nor intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Firefox that allowed\na remote attacker to conduct cross-site scripting (XSS) attacks.\n(CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nFirefox when using the Address Sanitizer tool. If a user were tricked into\nopening a specially crafted web page, a remote attacker could cause Firefox\nto crash or potentially execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3983","CVE-2012-3982","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3991","CVE-2012-3994","CVE-2012-3993","CVE-2012-4184","CVE-2012-3992","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-3990"]},{"id":"USN-1611-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1062587","https://launchpad.net/bugs/1065292"],"published":"2012-10-12T18:37:42.121496","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Thunderbird. If a user were\ntricked into opening a malicious website and had JavaScript enabled, an\nattacker could exploit these to execute arbitrary JavaScript code within\nthe context of another website or arbitrary code as the user invoking the\nprogram. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,\nCVE-2012-4191)\n\nDavid Bloom and Jordi Chancel discovered that Thunderbird did not always\nproperly handle the <select> element. If a user were tricked into opening a\nmalicious website and had JavaScript enabled, a remote attacker could\nexploit this to conduct URL spoofing and clickjacking attacks.\n(CVE-2012-3984)\n\nCollin Jackson discovered that Thunderbird did not properly follow the\nHTML5 specification for document.domain behavior. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, a remote\nattacker could exploit this to conduct cross-site scripting (XSS) attacks\nvia JavaScript execution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Thunderbird did not properly perform\nsecurity checks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page and had JavaScript enabled, a remote attacker could\nexploit this to execute arbitrary code as the user invoking the program.\n(CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Thunderbird. If a user\nwere tricked into opening a malicious website and had JavaScript enabled, a\nremote attacker could exploit this to spoof the location property to inject\nscript or intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Thunderbird that\nallowed a remote attacker to conduct cross-site scripting (XSS) attacks.\nWith cross-site scripting vulnerabilities, if a user were tricked into\nviewing a specially crafted page and had JavaScript enabled, a remote\nattacker could exploit these to modify the contents, or steal confidential\ndata, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nThunderbird when using the Address Sanitizer tool. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, an attacker\ncould exploit these to execute arbitrary JavaScript code within the context\nof another website or execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n\nIt was discovered that Thunderbird allowed improper access to the Location\nobject. An attacker could exploit this to obtain sensitive information.\nUnder certain circumstances, a remote attacker could use this vulnerability\nto potentially execute arbitrary code as the user invoking the program.\n(CVE-2012-4192, CVE-2012-4193)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3982","CVE-2012-3983","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3990","CVE-2012-3991","CVE-2012-3992","CVE-2012-3993","CVE-2012-3994","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4184","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-4191","CVE-2012-4192","CVE-2012-4193"]}]},{"id":"CVE-2012-3994","published":"2012-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird\nbefore 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13\nallow remote attackers to conduct cross-site scripting (XSS) attacks via a\nbinary plugin that uses Object.defineProperty to shadow the top object, and\nleverages the relationship between top.location and the location property.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1600-1","https://ubuntu.com/security/notices/USN-1611-1","https://www.cve.org/CVERecord?id=CVE-2012-3994"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1600-1","USN-1611-1"],"notices":[{"id":"USN-1600-1","title":"Firefox vulnerabilities","summary":"Multiple security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":[],"published":"2012-10-09T22:32:04.591059","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Firefox. If a user were\ntricked into opening a specially crafted web page, a remote attacker could\ncause Firefox to crash or potentially execute arbitrary code as the user\ninvoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,\nCVE-2012-3989)\n\nDavid Bloom and Jordi Chancel discovered that Firefox did not always\nproperly handle the <select> element. A remote attacker could exploit this\nto conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)\n\nCollin Jackson discovered that Firefox did not properly follow the HTML5\nspecification for document.domain behavior. A remote attacker could exploit\nthis to conduct cross-site scripting (XSS) attacks via javascript\nexecution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Firefox did not properly perform security\nchecks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page, a remote attacker could exploit this to execute arbitrary\ncode as the user invoking the program. (CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Firefox. A remote\nattacker could exploit this to spoof the location property to inject script\nor intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Firefox that allowed\na remote attacker to conduct cross-site scripting (XSS) attacks.\n(CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nFirefox when using the Address Sanitizer tool. If a user were tricked into\nopening a specially crafted web page, a remote attacker could cause Firefox\nto crash or potentially execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3983","CVE-2012-3982","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3991","CVE-2012-3994","CVE-2012-3993","CVE-2012-4184","CVE-2012-3992","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-3990"]},{"id":"USN-1611-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1062587","https://launchpad.net/bugs/1065292"],"published":"2012-10-12T18:37:42.121496","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Thunderbird. If a user were\ntricked into opening a malicious website and had JavaScript enabled, an\nattacker could exploit these to execute arbitrary JavaScript code within\nthe context of another website or arbitrary code as the user invoking the\nprogram. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,\nCVE-2012-4191)\n\nDavid Bloom and Jordi Chancel discovered that Thunderbird did not always\nproperly handle the <select> element. If a user were tricked into opening a\nmalicious website and had JavaScript enabled, a remote attacker could\nexploit this to conduct URL spoofing and clickjacking attacks.\n(CVE-2012-3984)\n\nCollin Jackson discovered that Thunderbird did not properly follow the\nHTML5 specification for document.domain behavior. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, a remote\nattacker could exploit this to conduct cross-site scripting (XSS) attacks\nvia JavaScript execution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Thunderbird did not properly perform\nsecurity checks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page and had JavaScript enabled, a remote attacker could\nexploit this to execute arbitrary code as the user invoking the program.\n(CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Thunderbird. If a user\nwere tricked into opening a malicious website and had JavaScript enabled, a\nremote attacker could exploit this to spoof the location property to inject\nscript or intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Thunderbird that\nallowed a remote attacker to conduct cross-site scripting (XSS) attacks.\nWith cross-site scripting vulnerabilities, if a user were tricked into\nviewing a specially crafted page and had JavaScript enabled, a remote\nattacker could exploit these to modify the contents, or steal confidential\ndata, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nThunderbird when using the Address Sanitizer tool. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, an attacker\ncould exploit these to execute arbitrary JavaScript code within the context\nof another website or execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n\nIt was discovered that Thunderbird allowed improper access to the Location\nobject. An attacker could exploit this to obtain sensitive information.\nUnder certain circumstances, a remote attacker could use this vulnerability\nto potentially execute arbitrary code as the user invoking the program.\n(CVE-2012-4192, CVE-2012-4193)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3982","CVE-2012-3983","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3990","CVE-2012-3991","CVE-2012-3992","CVE-2012-3993","CVE-2012-3994","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4184","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-4191","CVE-2012-4192","CVE-2012-4193"]}]},{"id":"CVE-2012-3993","published":"2012-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Chrome Object Wrapper (COW) implementation in Mozilla Firefox before\n16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird\nESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not properly\ninteract with failures of InstallTrigger methods, which allows remote\nattackers to execute arbitrary JavaScript code with chrome privileges via a\ncrafted web site, related to an \"XrayWrapper pollution\" issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1600-1","https://ubuntu.com/security/notices/USN-1611-1","https://www.cve.org/CVERecord?id=CVE-2012-3993"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1600-1","USN-1611-1"],"notices":[{"id":"USN-1600-1","title":"Firefox vulnerabilities","summary":"Multiple security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":[],"published":"2012-10-09T22:32:04.591059","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Firefox. If a user were\ntricked into opening a specially crafted web page, a remote attacker could\ncause Firefox to crash or potentially execute arbitrary code as the user\ninvoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,\nCVE-2012-3989)\n\nDavid Bloom and Jordi Chancel discovered that Firefox did not always\nproperly handle the <select> element. A remote attacker could exploit this\nto conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)\n\nCollin Jackson discovered that Firefox did not properly follow the HTML5\nspecification for document.domain behavior. A remote attacker could exploit\nthis to conduct cross-site scripting (XSS) attacks via javascript\nexecution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Firefox did not properly perform security\nchecks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page, a remote attacker could exploit this to execute arbitrary\ncode as the user invoking the program. (CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Firefox. A remote\nattacker could exploit this to spoof the location property to inject script\nor intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Firefox that allowed\na remote attacker to conduct cross-site scripting (XSS) attacks.\n(CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nFirefox when using the Address Sanitizer tool. If a user were tricked into\nopening a specially crafted web page, a remote attacker could cause Firefox\nto crash or potentially execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3983","CVE-2012-3982","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3991","CVE-2012-3994","CVE-2012-3993","CVE-2012-4184","CVE-2012-3992","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-3990"]},{"id":"USN-1611-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1062587","https://launchpad.net/bugs/1065292"],"published":"2012-10-12T18:37:42.121496","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Thunderbird. If a user were\ntricked into opening a malicious website and had JavaScript enabled, an\nattacker could exploit these to execute arbitrary JavaScript code within\nthe context of another website or arbitrary code as the user invoking the\nprogram. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,\nCVE-2012-4191)\n\nDavid Bloom and Jordi Chancel discovered that Thunderbird did not always\nproperly handle the <select> element. If a user were tricked into opening a\nmalicious website and had JavaScript enabled, a remote attacker could\nexploit this to conduct URL spoofing and clickjacking attacks.\n(CVE-2012-3984)\n\nCollin Jackson discovered that Thunderbird did not properly follow the\nHTML5 specification for document.domain behavior. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, a remote\nattacker could exploit this to conduct cross-site scripting (XSS) attacks\nvia JavaScript execution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Thunderbird did not properly perform\nsecurity checks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page and had JavaScript enabled, a remote attacker could\nexploit this to execute arbitrary code as the user invoking the program.\n(CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Thunderbird. If a user\nwere tricked into opening a malicious website and had JavaScript enabled, a\nremote attacker could exploit this to spoof the location property to inject\nscript or intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Thunderbird that\nallowed a remote attacker to conduct cross-site scripting (XSS) attacks.\nWith cross-site scripting vulnerabilities, if a user were tricked into\nviewing a specially crafted page and had JavaScript enabled, a remote\nattacker could exploit these to modify the contents, or steal confidential\ndata, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nThunderbird when using the Address Sanitizer tool. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, an attacker\ncould exploit these to execute arbitrary JavaScript code within the context\nof another website or execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n\nIt was discovered that Thunderbird allowed improper access to the Location\nobject. An attacker could exploit this to obtain sensitive information.\nUnder certain circumstances, a remote attacker could use this vulnerability\nto potentially execute arbitrary code as the user invoking the program.\n(CVE-2012-4192, CVE-2012-4193)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3982","CVE-2012-3983","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3990","CVE-2012-3991","CVE-2012-3992","CVE-2012-3993","CVE-2012-3994","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4184","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-4191","CVE-2012-4192","CVE-2012-4193"]}]},{"id":"CVE-2012-3992","published":"2012-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird\nbefore 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13\ndo not properly manage history data, which allows remote attackers to\nconduct cross-site scripting (XSS) attacks or obtain sensitive POST content\nvia vectors involving a location.hash write operation and history\nnavigation that triggers the loading of a URL into the history object.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1600-1","https://ubuntu.com/security/notices/USN-1611-1","https://www.cve.org/CVERecord?id=CVE-2012-3992"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"16.0+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"16.0+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"16.0+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"16.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"16.0.1+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.0","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1600-1","USN-1611-1"],"notices":[{"id":"USN-1600-1","title":"Firefox vulnerabilities","summary":"Multiple security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":[],"published":"2012-10-09T22:32:04.591059","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Firefox. If a user were\ntricked into opening a specially crafted web page, a remote attacker could\ncause Firefox to crash or potentially execute arbitrary code as the user\ninvoking the program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988,\nCVE-2012-3989)\n\nDavid Bloom and Jordi Chancel discovered that Firefox did not always\nproperly handle the <select> element. A remote attacker could exploit this\nto conduct URL spoofing and clickjacking attacks. (CVE-2012-3984)\n\nCollin Jackson discovered that Firefox did not properly follow the HTML5\nspecification for document.domain behavior. A remote attacker could exploit\nthis to conduct cross-site scripting (XSS) attacks via javascript\nexecution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Firefox did not properly perform security\nchecks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page, a remote attacker could exploit this to execute arbitrary\ncode as the user invoking the program. (CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Firefox. A remote\nattacker could exploit this to spoof the location property to inject script\nor intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Firefox that allowed\na remote attacker to conduct cross-site scripting (XSS) attacks.\n(CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nFirefox when using the Address Sanitizer tool. If a user were tricked into\nopening a specially crafted web page, a remote attacker could cause Firefox\nto crash or potentially execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"16.0+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/16.0+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3983","CVE-2012-3982","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3991","CVE-2012-3994","CVE-2012-3993","CVE-2012-4184","CVE-2012-3992","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-3990"]},{"id":"USN-1611-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1062587","https://launchpad.net/bugs/1065292"],"published":"2012-10-12T18:37:42.121496","description":"Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others\ndiscovered several memory corruption flaws in Thunderbird. If a user were\ntricked into opening a malicious website and had JavaScript enabled, an\nattacker could exploit these to execute arbitrary JavaScript code within\nthe context of another website or arbitrary code as the user invoking the\nprogram. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,\nCVE-2012-4191)\n\nDavid Bloom and Jordi Chancel discovered that Thunderbird did not always\nproperly handle the <select> element. If a user were tricked into opening a\nmalicious website and had JavaScript enabled, a remote attacker could\nexploit this to conduct URL spoofing and clickjacking attacks.\n(CVE-2012-3984)\n\nCollin Jackson discovered that Thunderbird did not properly follow the\nHTML5 specification for document.domain behavior. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, a remote\nattacker could exploit this to conduct cross-site scripting (XSS) attacks\nvia JavaScript execution. (CVE-2012-3985)\n\nJohnny Stenback discovered that Thunderbird did not properly perform\nsecurity checks on test methods for DOMWindowUtils. (CVE-2012-3986)\n\nAlice White discovered that the security checks for GetProperty could be\nbypassed when using JSAPI. If a user were tricked into opening a specially\ncrafted web page and had JavaScript enabled, a remote attacker could\nexploit this to execute arbitrary code as the user invoking the program.\n(CVE-2012-3991)\n\nMariusz Mlynski discovered a history state error in Thunderbird. If a user\nwere tricked into opening a malicious website and had JavaScript enabled, a\nremote attacker could exploit this to spoof the location property to inject\nscript or intercept posted data. (CVE-2012-3992)\n\nMariusz Mlynski and others discovered several flaws in Thunderbird that\nallowed a remote attacker to conduct cross-site scripting (XSS) attacks.\nWith cross-site scripting vulnerabilities, if a user were tricked into\nviewing a specially crafted page and had JavaScript enabled, a remote\nattacker could exploit these to modify the contents, or steal confidential\ndata, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)\n\nAbhishek Arya, Atte Kettunen and others discovered several memory flaws in\nThunderbird when using the Address Sanitizer tool. If a user were tricked\ninto opening a malicious website and had JavaScript enabled, an attacker\ncould exploit these to execute arbitrary JavaScript code within the context\nof another website or execute arbitrary code as the user invoking the\nprogram. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,\nCVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,\nCVE-2012-4187, CVE-2012-4188)\n\nIt was discovered that Thunderbird allowed improper access to the Location\nobject. An attacker could exploit this to obtain sensitive information.\nUnder certain circumstances, a remote attacker could use this vulnerability\nto potentially execute arbitrary code as the user invoking the program.\n(CVE-2012-4192, CVE-2012-4193)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.10.04.1"}],"natty":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"16.0.1+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/16.0.1+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3982","CVE-2012-3983","CVE-2012-3984","CVE-2012-3985","CVE-2012-3986","CVE-2012-3988","CVE-2012-3989","CVE-2012-3990","CVE-2012-3991","CVE-2012-3992","CVE-2012-3993","CVE-2012-3994","CVE-2012-3995","CVE-2012-4179","CVE-2012-4180","CVE-2012-4181","CVE-2012-4182","CVE-2012-4183","CVE-2012-4184","CVE-2012-4185","CVE-2012-4186","CVE-2012-4187","CVE-2012-4188","CVE-2012-4191","CVE-2012-4192","CVE-2012-4193"]}]}],"offset":68780,"limit":20,"total_results":79316}