CVE-2011-3660

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger a compartment mismatch associated with the nsDOMMessageEvent::GetData function, and unknown other vectors.

References

http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00001.html

http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00009.html

http://osvdb.org/77952

http://secunia.com/advisories/47302

http://secunia.com/advisories/47334

http://secunia.com/advisories/49055

http://www.mandriva.com/security/advisories?name=MDVSA-2011:192

http://www.mozilla.org/security/announce/2011/mfsa2011-53.html

http://www.securitytracker.com/id?1026445

http://www.securitytracker.com/id?1026446

http://www.securitytracker.com/id?1026447

https://bugzilla.mozilla.org/show_bug.cgi?id=562442

https://bugzilla.mozilla.org/show_bug.cgi?id=679494

https://bugzilla.mozilla.org/show_bug.cgi?id=679986

https://bugzilla.mozilla.org/show_bug.cgi?id=680687

https://bugzilla.mozilla.org/show_bug.cgi?id=682252

https://bugzilla.mozilla.org/show_bug.cgi?id=685186

https://bugzilla.mozilla.org/show_bug.cgi?id=685321

https://bugzilla.mozilla.org/show_bug.cgi?id=686107

https://bugzilla.mozilla.org/show_bug.cgi?id=688364

https://bugzilla.mozilla.org/show_bug.cgi?id=688974

https://bugzilla.mozilla.org/show_bug.cgi?id=689892

https://bugzilla.mozilla.org/show_bug.cgi?id=690376

https://bugzilla.mozilla.org/show_bug.cgi?id=691746

https://bugzilla.mozilla.org/show_bug.cgi?id=691873

https://bugzilla.mozilla.org/show_bug.cgi?id=693143

https://bugzilla.mozilla.org/show_bug.cgi?id=693144

https://bugzilla.mozilla.org/show_bug.cgi?id=694200

https://bugzilla.mozilla.org/show_bug.cgi?id=696579

https://bugzilla.mozilla.org/show_bug.cgi?id=697255

https://bugzilla.mozilla.org/show_bug.cgi?id=700512

https://bugzilla.mozilla.org/show_bug.cgi?id=701248

https://bugzilla.mozilla.org/show_bug.cgi?id=701637

https://bugzilla.mozilla.org/show_bug.cgi?id=706249

https://exchange.xforce.ibmcloud.com/vulnerabilities/71908

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14226

Details

Source: MITRE

Published: 2011-12-21

Updated: 2017-09-19

Risk Information

CVSS v2

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:mozilla:firefox:4.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:4.0:beta1:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:4.0:beta10:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:4.0:beta11:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:4.0:beta12:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:4.0:beta2:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:4.0:beta3:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:4.0:beta4:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:4.0:beta5:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:4.0:beta6:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:4.0:beta7:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:4.0:beta8:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:4.0:beta9:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:4.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:5.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:5.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:6.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:6.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:6.0.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:7.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:7.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:8.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0:*:beta:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0:*:dev:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0:alpha:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.4:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.7:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.8:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.9:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.99:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1:alpha:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1:beta:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.3:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.4:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.5:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.5:1.1.10:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.6:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.7:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.8:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.9:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.10:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.11:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.12:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.13:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.14:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.15:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.16:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.17:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.18:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.19:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.5.0.8:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.5.0.9:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.5.0.10:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0:beta_1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0:beta_2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0:rc1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0:rc2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.3:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.4:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.5:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.6:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.7:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.8:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.9:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.10:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.11:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.12:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.13:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.14:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0a1:*:pre:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0a1pre:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.1:alpha1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.1:alpha2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.1:alpha3:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.3.3:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* versions up to 2.5 (inclusive)

cpe:2.3:a:mozilla:thunderbird:5.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:6.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:6.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:6.0.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:7.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:7.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:8.0:*:*:*:*:*:*:*

Tenable Plugins

View all (20 total)

IDNameProductFamilySeverity
76025openSUSE Security Update : seamonkey (openSUSE-SU-2012:0007-1)NessusSuSE Local Security Checks
critical
75950openSUSE Security Update : MozillaFirefox (openSUSE-SU-2012:0039-2)NessusSuSE Local Security Checks
critical
75744openSUSE Security Update : seamonkey (openSUSE-SU-2012:0007-1)NessusSuSE Local Security Checks
critical
74612openSUSE Security Update : MozillaFirefox / MozillaThunderbird / seamonkey / etc (openSUSE-SU-2012:0567-1)NessusSuSE Local Security Checks
critical
74515openSUSE Security Update : MozillaFirefox / MozillaThunderbird / seamonkey / etc (openSUSE-2011-101)NessusSuSE Local Security Checks
critical
63402GLSA-201301-01 : Mozilla Products: Multiple vulnerabilities (BEAST)NessusGentoo Local Security Checks
critical
61940Mandriva Linux Security Advisory : mozilla (MDVSA-2011:192)NessusMandriva Local Security Checks
critical
57686Ubuntu 11.10 : thunderbird vulnerabilities (USN-1343-1)NessusUbuntu Local Security Checks
critical
57458Ubuntu 11.04 / 11.10 : mozvoikko, ubufox update (USN-1306-2)NessusUbuntu Local Security Checks
critical
57457Ubuntu 11.04 / 11.10 : firefox vulnerabilities (USN-1306-1)NessusUbuntu Local Security Checks
critical
801379Mozilla Firefox 8.0 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
6109Mozilla Firefox < 9.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
57361Thunderbird 8.x Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
57359Firefox 8.x Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
57355FreeBSD : mozilla -- multiple vulnerabilities (e3ff776b-2ba6-11e1-93c6-0011856a6e37)NessusFreeBSD Local Security Checks
critical
57353SeaMonkey < 2.6.0 Multiple VulnerabilitiesNessusWindows
high
57352Mozilla Thunderbird < 9.0 Multiple VulnerabilitiesNessusWindows
high
57351Firefox < 9.0 Multiple VulnerabilitiesNessusWindows
high
801222Mozilla Thunderbird 8 Multiple VulnerabilitiesLog Correlation EngineSMTP Clients
high
6110Mozilla Thunderbird < 9.0 Multiple Vulnerabilities (deprecated)Nessus Network MonitorSMTP Clients
high