CVE-2012-0444

CRITICAL

Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remot...

Affects 9 products across 5 vendors.

BCS7.85
CVSS 2.010.0
EPSS7.9%
Percentile94th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-119: Improper Restriction of Operations within Memory Buffer

Parent class for buffer-related vulnerabilities where operations exceed buffer boundaries.

Related Attack Patterns (CAPEC)
CAPEC-8 Buffer Overflow in an API Call
via CWE-119
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-119
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-119
CAPEC-14 Client-side Injection-induced Buffer Overflow
via CWE-119
CAPEC-24 Filter Failure through Buffer Overflow
via CWE-119
Show all 12

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2012. A critical vulnerability affects Canonical systems (CVE-2012-0444). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2012-GLOBAL-090047-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2012-0444?
This vulnerability was disclosed in 2012. A critical vulnerability affects Canonical systems (CVE-2012-0444). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2012-0444?
CVE-2012-0444 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 7.9%.
Is CVE-2012-0444 actively exploited?
No confirmed active exploitation of CVE-2012-0444 as of 2026-05-30.
How do I remediate CVE-2012-0444?
Priority: MEDIUM.
What systems are affected by CVE-2012-0444?
CVE-2012-0444 affects: Canonical, Debian, Mozilla, Mozilla, Mozilla, Opensuse, Suse, Suse.
Vulnerability Details
CVE IDCVE-2012-0444
BSIDBS-2012-GLOBAL-090047-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2012-02-01
Last Modified2026-04-29
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Canonical Ubuntu Linux
Debian Debian Linux
Mozilla Firefox
Mozilla Thunderbird
Mozilla Seamonkey
Opensuse Opensuse
Suse Linux Enterprise Desktop
Suse Linux Enterprise Software Development Kit
Suse Linux Enterprise Server
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 5295 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashe5244141097090049d88e9520d5e45e069393755714dcc8d879a57293ce537881449ced94ec8b998d9d29648e82bd05cc8cbf6d641000a5dfbffff0edec40342
Related CVEs affecting Canonical
CVE-2004-1018 10.0 Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypa... CVE-2004-1063 10.0 PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multit... CVE-2007-2442 10.0 The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb... CVE-2012-4212 10.0 Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozill... CVE-2008-2663 10.0 Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and ear...
View all Canonical CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →