CVE-2012-4212

CRITICAL

Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary c...

Affects 8 products across 4 vendors.

BCS7.63
CVSS 2.010.0
EPSS5.6%
Percentile92th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-416: Use After Free

Software references memory after it has been freed, leading to corruption, crashes, or code execution.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2012. A critical vulnerability affects Canonical systems (CVE-2012-4212). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2012-GLOBAL-092037-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2012-4212?
This vulnerability was disclosed in 2012. A critical vulnerability affects Canonical systems (CVE-2012-4212). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2012-4212?
CVE-2012-4212 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 5.6%.
Is CVE-2012-4212 actively exploited?
No confirmed active exploitation of CVE-2012-4212 as of 2026-05-30.
How do I remediate CVE-2012-4212?
Priority: MEDIUM. Advisory: http://www.mozilla.org/security/announce/2012/mfsa2012-105.html PSIRT: [email protected]
What systems are affected by CVE-2012-4212?
CVE-2012-4212 affects: Canonical, Mozilla, Mozilla, Mozilla, Opensuse, Suse, Suse, Suse.
Vulnerability Details
CVE IDCVE-2012-4212
BSIDBS-2012-GLOBAL-092037-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2012-11-21
Last Modified2026-04-29
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Canonical Ubuntu Linux
Mozilla Thunderbird
Mozilla Seamonkey
Mozilla Firefox
Opensuse Opensuse
Suse Linux Enterprise Software Development Kit
Suse Linux Enterprise Server
Suse Linux Enterprise Desktop
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 5002 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash539bc72ecd64492085eadf34bbe3da9639a87290e316242742994170987ba8008bb8190417da31e006ba5a271958d1e8faa2d49f5185ca263780d9419603d977
Related CVEs affecting Canonical
CVE-2012-0444 10.0 Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 ... CVE-2004-1018 10.0 Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypa... CVE-2004-1063 10.0 PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multit... CVE-2007-2442 10.0 The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb... CVE-2007-0063 10.0 Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 B...
View all Canonical CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →