The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used in Mozilla Firefox before 38.0 and other products, does not properly validate messages, which has unspecified impact and attack vectors.
2012-05-01T10:12:04.157
2025-04-11T00:51:21.963
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | opensuse | opensuse | 13.1 | Yes |
| Operating System | opensuse | opensuse | 13.2 | Yes |
| Application | chrome | ≤ 18.0.1025.166 | Yes | |
| Application | mozilla | firefox | ≤ 37.0.2 | Yes |
| Application | mozilla | firefox_esr | ≤ 31.6 | Yes |
| Application | mozilla | seamonkey | ≤ 2.33.0 | Yes |
| Application | mozilla | thunderbird | ≤ 31.6 | Yes |
| Application | mozilla | thunderbird | ≤ 38.0 | Yes |