CVE-2011-3655

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Mozilla Firefox 4.x through 7.0 and Thunderbird 5.0 through 7.0 perform access control without checking for use of the NoWaiverWrapper wrapper, which allows remote attackers to gain privileges via a crafted web site.

References

http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.html

http://secunia.com/advisories/49055

http://www.mozilla.org/security/announce/2011/mfsa2011-52.html

https://bugzilla.mozilla.org/show_bug.cgi?id=672182

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14202

Details

Source: MITRE

Published: 2011-11-09

Updated: 2017-09-19

Type: CWE-94

Risk Information

CVSS v2

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

Tenable Plugins

View all (24 total)

IDNameProductFamilySeverity
80783Oracle Solaris Third-Party Patch Update : thunderbird (multiple_vulnerabilities_in_thunderbird2)NessusSolaris Local Security Checks
critical
80608Oracle Solaris Third-Party Patch Update : firefox (multiple_vulnerabilities_in_mozilla_firefox1)NessusSolaris Local Security Checks
critical
76024openSUSE Security Update : seamonkey (openSUSE-SU-2011:1290-1)NessusSuSE Local Security Checks
critical
75949openSUSE Security Update : MozillaFirefox (openSUSE-SU-2011:1243-1)NessusSuSE Local Security Checks
critical
75743openSUSE Security Update : seamonkey (openSUSE-SU-2011:1290-1)NessusSuSE Local Security Checks
critical
74612openSUSE Security Update : MozillaFirefox / MozillaThunderbird / seamonkey / etc (openSUSE-SU-2012:0567-1)NessusSuSE Local Security Checks
critical
74542openSUSE Security Update : firefox / thunderbird (openSUSE-2011-9)NessusSuSE Local Security Checks
critical
74522openSUSE Security Update : seamonkey (openSUSE-2011-34)NessusSuSE Local Security Checks
critical
801321Mozilla Firefox 7.0 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801281Mozilla Thunderbird 7.0 Multiple VulnerabilitiesLog Correlation EngineSMTP Clients
high
6789Mozilla Thunderbird < 8.0 Multiple VulnerabilitiesNessus Network MonitorSMTP Clients
high
6788Mozilla Firefox < 8.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
63402GLSA-201301-01 : Mozilla Products: Multiple vulnerabilities (BEAST)NessusGentoo Local Security Checks
critical
57226SuSE 10 Security Update : mozilla-nss (ZYPP Patch Number 7842) (BEAST)NessusSuSE Local Security Checks
critical
57084SuSE 11.1 Security Update : Mozilla Firefox (SAT Patch Number 5429)NessusSuSE Local Security Checks
critical
56969Ubuntu 11.10 : thunderbird vulnerabilities (USN-1282-1)NessusUbuntu Local Security Checks
critical
56945Ubuntu 11.04 / 11.10 : mozvoikko, ubufox update (USN-1277-2)NessusUbuntu Local Security Checks
critical
56944Ubuntu 11.04 / 11.10 : firefox vulnerabilities (USN-1277-1)NessusUbuntu Local Security Checks
critical
56765Mandriva Linux Security Advisory : mozilla (MDVSA-2011:169)NessusMandriva Local Security Checks
critical
56762FreeBSD : mozilla -- multiple vulnerabilities (6c8ad3e8-0a30-11e1-9580-4061862b8c22)NessusFreeBSD Local Security Checks
critical
56758Thunderbird 7.x Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
56756Firefox < 8.0 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
56753Mozilla Thunderbird < 8.0 Multiple VulnerabilitiesNessusWindows
high
56751Firefox < 8.0 Multiple VulnerabilitiesNessusWindows
high