CVE-2011-2987

HIGH

Description

Heap-based buffer overflow in Almost Native Graphics Layer Engine (ANGLE), as used in the WebGL implementation in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products might allow remote attackers to execute arbitrary code via unspecified vectors.

References

http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00023.html

http://secunia.com/advisories/49055

http://www.mozilla.org/security/announce/2011/mfsa2011-29.html

http://www.mozilla.org/security/announce/2011/mfsa2011-31.html

http://www.mozilla.org/security/announce/2011/mfsa2011-33.html

http://www.securityfocus.com/bid/49226

https://bugzilla.mozilla.org/show_bug.cgi?id=665934

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14285

Details

Source: MITRE

Published: 2011-08-18

Updated: 2017-09-19

Type: CWE-119

Risk Information

CVSS v2.0

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH