The FT2FontEntry::CreateFontEntry function in FreeType, as used in the Android build of Mozilla Firefox before 16.0.1 on CyanogenMod 10, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-thunderbirdUpgrade thunderbirdUpgrade linux-seamonkeyUpgrade linux-firefoxUpgrade seamonkeyUpgrade libxulUpgrade firefox | Dec 10, 2025 | Oct 10, 2012 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade www-client/icecat.Upgrade mail-client/thunderbird.Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey-bin.Upgrade dev-libs/nss.Upgrade www-client/seamonkey.Upgrade www-client/firefox.Upgrade net-libs/xulrunner.Upgrade net-libs/xulrunner-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/thunderbird-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/mozilla-thunderbird-bin. | Oct 30, 2017 | Oct 12, 2012 |
| Mfsa2012 88 | — | Upgrade to Mozilla Firefox version 16.0.1Upgrade to the latest version of Mozilla Firefox | Oct 16, 2012 | Oct 12, 2012 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.13.1 | Oct 16, 2012 | Oct 12, 2012 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 16.0.1Upgrade to the latest version of Mozilla Thunderbird | Oct 16, 2012 | Oct 12, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub