CVE-2012-0468: Mozilla Firefox

High severity, CVSS 10.0. EPSS: 4.2% chance of exploitation in the next 30 days.

The browser engine in Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (assertion failure and memory corruption) or possibly execute arbitrary code via vectors related to jsval.h and the js::array_shift function.

Affected products

  • Mozilla Firefox: version 4.0 only; version 4.0.1 only; version 5.0 only; version 5.0.1 only; version 6.0 only; version 6.0.1 only; …
  • Mozilla Seamonkey: up to and including 2.9; version 1.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; …
  • Mozilla Thunderbird: version 5.0 only; version 6.0 only; version 6.0.1 only; version 6.0.2 only; version 7.0 only; version 7.0.1 only; …

Published 2012-04-25. Last modified 2026-06-16.