CVE-2012-0444: Canonical Ubuntu Linux
High severity, CVSS 10.0. EPSS: 7.8% chance of exploitation in the next 30 days.
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.
Affected products
- Canonical Ubuntu Linux: version 10.04 only; version 10.10 only; version 11.04 only; version 11.10 only
- Debian Debian Linux: version 5.0 only; version 6.0 only
- Mozilla Firefox: before 3.6.26 (fixed in 3.6.26); from 4.0, before 10.0 (fixed in 10.0)
- Mozilla Seamonkey: before 2.7 (fixed in 2.7)
- Mozilla Thunderbird: before 3.1.18 (fixed in 3.1.18); from 5.0, before 10.0 (fixed in 10.0)
- Opensuse Opensuse: version 11.4 only
- Suse Linux Enterprise Desktop: version 10 only; version 11 only
- Suse Linux Enterprise Server: version 10 only; version 11 only
- Suse Linux Enterprise Software Development Kit: version 10 only; version 11 only
Published 2012-02-01. Last modified 2026-06-16.