CVE-2012-0478 describes a critical vulnerability in the WebGL subsystem of Mozilla Firefox, Thunderbird, and SeaMonkey versions prior to their respective patches. This flaw, specifically in the texImage2D implementation, improperly handles JSVAL_TO_OBJECT casts, potentially allowing remote attackers to execute arbitrary code through a specially crafted web page. With a CVSS score of 9.3, it represents a high-severity risk, requiring no authentication and moderate attack complexity to achieve complete compromise of confidentiality, integrity, and availability. While no public exploit intelligence like Metasploit modules or ExploitDB entries are available, and there's no evidence of active exploitation or significant community discussion, the potential for remote code execution warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:4.0:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:4.0:beta1:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:4.0:beta10:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:4.0:beta11:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:4.0:beta12:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.