Use-after-free vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 on 32-bit Windows 7 platforms allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving use of the file-open dialog in a child window, related to the IUnknown_QueryService function in the Windows shlwapi.dll library.
                
            References
                    Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
Configuration 2 (hide)
| AND | 
            
            
 
  | 
    
Configuration 3 (hide)
| AND | 
            
            
 
  | 
    
Configuration 4 (hide)
| AND | 
            
            
 
  | 
    
Configuration 5 (hide)
| AND | 
            
            
 
  | 
    
History
                    No history.
Information
                Published : 2012-03-14 19:55
Updated : 2025-04-11 00:51
NVD link : CVE-2012-0454
Mitre link : CVE-2012-0454
CVE.ORG link : CVE-2012-0454
JSON object : View
Products Affected
                mozilla
- firefox_esr
 - seamonkey
 - thunderbird_esr
 - firefox
 - thunderbird
 
microsoft
- windows_7
 
CWE
                
                    
                        
                        CWE-399
                        
            Resource Management Errors
