CVE-2012-0449: Debian Linux

High severity, CVSS 9.3. EPSS: 5.7% chance of exploitation in the next 30 days.

Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.

Affected products

  • Debian Debian Linux: version 5.0 only; version 6.0 only
  • Mozilla Firefox: before 3.6.26 (fixed in 3.6.26); from 4.0, before 10.0 (fixed in 10.0)
  • Mozilla Seamonkey: before 2.7 (fixed in 2.7)
  • Mozilla Thunderbird: before 3.1.18 (fixed in 3.1.18); from 5.0, before 10.0 (fixed in 10.0)
  • Opensuse Opensuse: version 11.4 only
  • Suse Linux Enterprise Desktop: version 10 only; version 11 only
  • Suse Linux Enterprise Server: version 10 only; version 11 only
  • Suse Linux Enterprise Software Development Kit: version 10 only; version 11 only

Published 2012-02-01. Last modified 2026-06-16.