FirefoxWeb browser · Mozilla

CVE-2012-3967

HIGH · 9.3 CVSS v2.0 Published 2012-08-29
Fix available
A fix is available. Upgrade to 2.12 / 10.0.7 or later.
See remediation →
100/100
Remediation priority · Urgent
Public exploit Remotely reachable No privileges Zero-click Patch available

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
The WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 on Linux, when a large number of sampler uniforms are used, does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a crafted web site.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis
How this class of weakness works · CWE-787

The program writes past the bounds of a buffer, overwriting adjacent memory an attacker can turn to their advantage. Crafted input can overwrite control data and redirect execution. Remediation is validating every index and length before a write, plus modern memory-safety mitigations.

General guidance for the out-of-bounds write class — the official description and references above are authoritative for this specific CVE. Want a bespoke review and a reviewed fix? Ask our team →

Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.

NVD · CPE data
FirefoxWeb browser
Affected:< 15.0>= 10.0, < 10.0.7
Enterprise Linux DesktopOperating system
Affected:= 5.0= 6.0
Enterprise Linux EusOperating system
Affected:= 6.3
Enterprise Linux ServerOperating system
Affected:= 5.0= 6.0
Enterprise Linux WorkstationOperating system
Affected:= 5.0= 6.0
Ubuntu LinuxOperating system
Affected:= 10.04= 11.04= 11.10= 12.04
SeamonkeyApplication
Affected:< 2.12
ThunderbirdApplication
Affected:< 15.0

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
M
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete

AV:N/AC:M/Au:N/C:C/I:C/A:C

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Upgrade available Upgrade to 2.12 / 10.0.7 / 15.0 or later
Fixed in 2.1210.0.715.0
Recommended fix High confidence

Firefox 15.0+, Firefox ESR 10.0.7+, Thunderbird 15.0+, Thunderbird ESR 10.0.7+, SeaMonkey 2.12+

  1. Identify the installed Mozilla product (Firefox, Thunderbird, or SeaMonkey) and current version
  2. Back up browser profile data (bookmarks, passwords, extensions) before upgrading
  3. For Ubuntu/Debian systems: Run 'sudo apt-get update && sudo apt-get upgrade' or use Software Center to update to the fixed version
  4. For RHEL/CentOS systems: Run 'sudo yum update' or 'sudo up2date' to apply security updates
  5. For Firefox ESR 10.x users: Upgrade to Firefox ESR 10.0.7 or later, or migrate to a supported ESR branch
  6. Verify the upgrade was successful by checking Help > About in the application
Caveat Upgrading to newer major releases may require reconfiguration of extensions/add-ons or reset of custom preferences; ESR 10.0.7 is a security maintenance release with minimal behavioral changes

Generated from the published advisory — verify against the referenced sources before acting.

We can perform the upgrade in your staging environment and verify nothing breaks — typical engagement from $3,200. Get the upgrade done

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2012-3967 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2012-3967 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data