CVE-2012-4185
CVE-2012-4185 is a buffer overflow vulnerability in the nsCharTraits::length function affecting Mozilla Firefox, Firefox ESR, Thunderbird, Thunderbird ESR, and SeaMonkey. This flaw allows remote attackers to execute arbitrary code or cause a denial of service due to heap memory corruption. With a CVSS score of 9.3, it is considered critical, requiring no authentication and having medium attack complexity, leading to complete compromise of confidentiality, integrity, and availability. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is there evidence of active exploitation, and it has received minimal community discussion or media coverage.
Impacted Technologies
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.8CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 10.0.8CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:* | ||
< 16.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 16.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
< 2.13CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* |
CVSS Data
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploit Intelligence
Social Chatter
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
Media Mentions
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.