CVE-2011-2996

HIGH
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Unspecified vulnerability in the plugin API in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

References

http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.html

http://www.mandriva.com/security/advisories?name=MDVSA-2011:139

http://www.mandriva.com/security/advisories?name=MDVSA-2011:140

http://www.mozilla.org/security/announce/2011/mfsa2011-36.html

https://bugzilla.mozilla.org/show_bug.cgi?id=555018

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14064

Details

Source: MITRE

Published: 2011-09-29

Updated: 2017-09-19

Risk Information

CVSS v2

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH

Tenable Plugins

View all (20 total)

IDNameProductFamilySeverity
76024openSUSE Security Update : seamonkey (openSUSE-SU-2011:1290-1)NessusSuSE Local Security Checks
critical
75960openSUSE Security Update : mozilla-js192 (openSUSE-SU-2011:1076-1)NessusSuSE Local Security Checks
critical
75743openSUSE Security Update : seamonkey (openSUSE-SU-2011:1290-1)NessusSuSE Local Security Checks
critical
75656openSUSE Security Update : MozillaFirefox (openSUSE-SU-2011:1079-1)NessusSuSE Local Security Checks
critical
74542openSUSE Security Update : firefox / thunderbird (openSUSE-2011-9)NessusSuSE Local Security Checks
critical
63402GLSA-201301-01 : Mozilla Products: Multiple vulnerabilities (BEAST)NessusGentoo Local Security Checks
critical
57226SuSE 10 Security Update : mozilla-nss (ZYPP Patch Number 7842) (BEAST)NessusSuSE Local Security Checks
critical
57152SuSE 10 Security Update : Mozilla Firefox (ZYPP Patch Number 7784)NessusSuSE Local Security Checks
critical
57084SuSE 11.1 Security Update : Mozilla Firefox (SAT Patch Number 5429)NessusSuSE Local Security Checks
critical
57083SuSE 11.1 Security Update : Mozilla Firefox (SAT Patch Number 5224)NessusSuSE Local Security Checks
critical
56609SuSE 10 Security Update : Mozilla Firefox (ZYPP Patch Number 7783)NessusSuSE Local Security Checks
critical
56376Firefox 3.6 < 3.6.23 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
56374Mandriva Linux Security Advisory : mozilla-thunderbird (MDVSA-2011:140)NessusMandriva Local Security Checks
critical
56373Mandriva Linux Security Advisory : firefox (MDVSA-2011:139)NessusMandriva Local Security Checks
critical
801241Mozilla Firefox 3.6 < 3.6.23 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
6027Mozilla Firefox 3.6 < 3.6.23 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
56334Firefox 3.6.x < 3.6.23 Multiple VulnerabilitiesNessusWindows
high
56331Ubuntu 10.04 LTS / 10.10 / 11.04 : thunderbird vulnerabilities (USN-1213-1)NessusUbuntu Local Security Checks
critical
56330Ubuntu 10.04 LTS / 10.10 : firefox, xulrunner-1.9.2 vulnerabilities (USN-1210-1)NessusUbuntu Local Security Checks
critical
56323FreeBSD : Mozilla -- multiple vulnerabilities (1fade8a3-e9e8-11e0-9580-4061862b8c22)NessusFreeBSD Local Security Checks
critical