CVE-2011-0051
published 2011-03-02CVE-2011-0051: Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, does not properly handle certain recursive eval calls, which makes it…
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.82%
76.6th percentile
Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, does not properly handle certain recursive eval calls, which makes it easier for remote attackers to force a user to respond positively to a dialog question, as demonstrated by a question about granting privileges.
Affected
143 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.5.16 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_ubuntu9.3CRITICAL
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: kvm: pit timer with no irqchip crashes the system
vendor_redhat·2011-12-14·CVSS 4.9
CVE-2011-4622 [MEDIUM] kernel: kvm: pit timer with no irqchip crashes the system
kernel: kvm: pit timer with no irqchip crashes the system
The create_pit_timer function in arch/x86/kvm/i8254.c in KVM 83, and possibly other versions, does not properly handle when Programmable Interval Timer (PIT) interrupt requests (IRQs) when a virtual interrupt controller (irqchip) is not available, which allows local users to cause a denial of service (NULL pointer dereference) by starting a timer.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 and Red Hat Enterprise MRG as they did not provide support for the KVM subsystem. It has been addressed in Red Hat Enterprise 5 and 6 via https://rhn.redhat.com/errata/RHSA-2012-0051.html and https://rhn.redhat.com/errata/RHSA-2012-0350.html.
Package: kernel (Red Hat Enterprise L
Ubuntu
Xulrunner vulnerabilities
vendor_ubuntu·2011-04-30
CVE-2011-0077 Xulrunner vulnerabilities
Title: Xulrunner vulnerabilities
Summary: Multiple xulrunner-1.9.1 vulnerabilities
A large number of security issues were discovered in the Gecko rendering
engine. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: After a standard system update you need to restart any applications which
use Xulrunner to make all the necessary changes.
Ubuntu
Firefox and Xulrunner regression
vendor_ubuntu·2011-03-07·CVSS 6.8
[MEDIUM] Firefox and Xulrunner regression
Title: Firefox and Xulrunner regression
Summary: Fixed Java applet regression introduced in the update for USN 1049-1
USN-1049-1 fixed vulnerabilities in Firefox and Xulrunner. That update
introduced a regression where some Java applets would fail to load. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Jesse Ruderman, Igor Bukanov, Olli Pettay, Gary Kwong, Jeff Walden, Henry
Sivonen, Martijn Wargers, David Baron and Marcia Knous discovered several
memory issues in the browser engine. An attacker could exploit these to
crash the browser or possibly run arbitrary code as the user invoking the
program. (CVE-2011-0053, CVE-2011-0062)
Zach Hoffman discovered that a recursive call to eval() wrapped in a
try/catch statement places the browser i
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2011-03-03·CVSS 9.3
CVE-2011-0053 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Multiple browser flaws
Jesse Ruderman, Igor Bukanov, Olli Pettay, Gary Kwong, Jeff Walden, Henry
Sivonen, Martijn Wargers, David Baron and Marcia Knous discovered several
memory issues in the browser engine. An attacker could exploit these to
crash the browser or possibly run arbitrary code as the user invoking the
program. (CVE-2011-0053, CVE-2011-0062)
Zach Hoffman discovered that a recursive call to eval() wrapped in a
try/catch statement places the browser into a inconsistent state. An
attacker could exploit this to force a user to accept any dialog.
(CVE-2011-0051)
It was discovered that memory was used after being freed in a method used
by JSON.stringify. An attacker could exploit this to crash the browser or
possibly run arbi
Red Hat
Mozilla recursive eval call causes confirm dialog to evaluate to true (MFSA 2011-02)
vendor_redhat·2011-03-01·CVSS 6.8
CVE-2011-0051 [MEDIUM] Mozilla recursive eval call causes confirm dialog to evaluate to true (MFSA 2011-02)
Mozilla recursive eval call causes confirm dialog to evaluate to true (MFSA 2011-02)
Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, does not properly handle certain recursive eval calls, which makes it easier for remote attackers to force a user to respond positively to a dialog question, as demonstrated by a question about granting privileges.
Package: firefox (Red Hat Enterprise Linux Extended Update Support 4.8) - Affected
Package: seamonkey (Red Hat Enterprise Linux Extended Update Support 4.8) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update Support 4.8) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 5.6) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update Support 5
GHSA
GHSA-5mc6-qvmv-p3f9: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-03
CVE-2011-0051 [MEDIUM] CWE-20 GHSA-5mc6-qvmv-p3f9: Mozilla Firefox before 3
Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, does not properly handle certain recursive eval calls, which makes it easier for remote attackers to force a user to respond positively to a dialog question, as demonstrated by a question about granting privileges.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0051 Mozilla recursive eval call causes confirm dialog to evaluate to true (MFSA 2011-02)
bugzilla·2011-02-04·CVSS 6.8
CVE-2011-0051 [MEDIUM] CVE-2011-0051 Mozilla recursive eval call causes confirm dialog to evaluate to true (MFSA 2011-02)
CVE-2011-0051 Mozilla recursive eval call causes confirm dialog to evaluate to true (MFSA 2011-02)
Security researcher Zach Hoffman reported that a recursive call
to eval() wrapped in a try/catch statement places the browser
into a inconsistent state. Any dialog box opened in this state is
displayed without text and with non-functioning buttons.
Closing the window causes the dialog to evaluate to true.
An attacker could use this issue to force a user into accepting
any dialog, such as one granting elevated privileges to the page
presenting the dialog.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-02.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Bugzilla
CVE-2010-4225 mod_mono: remote source code exposure flaw
bugzilla·2011-01-12·CVSS 5.0
CVE-2010-4225 [MEDIUM] CVE-2010-4225 mod_mono: remote source code exposure flaw
CVE-2010-4225 mod_mono: remote source code exposure flaw
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4225 to
the following vulnerability:
Name: CVE-2010-4225
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4225
Assigned: 20101110
Reference: CONFIRM: http://www.mono-project.com/Vulnerabilities#XSP.2Fmod_mono_source_code_disclosure
Reference: BID:45711
Reference: URL: http://www.securityfocus.com/bid/45711
Reference: OSVDB:70312
Reference: URL: http://osvdb.org/70312
Reference: SECUNIA:42842
Reference: URL: http://secunia.com/advisories/42842
Reference: VUPEN:ADV-2011-0051
Reference: URL: http://www.vupen.com/english/advisories/2011/0051
Reference: XF:mono-modmono-source-disclosure(64532)
Reference: URL: http://xforce.iss.net/xforce/xfdb/64532
Unspecif
http://downloads.avaya.com/css/P8/documents/100133195http://support.avaya.com/css/P8/documents/100128655http://www.mandriva.com/security/advisories?name=MDVSA-2011:041http://www.mozilla.org/security/announce/2011/mfsa2011-02.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0312.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0313.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=616659https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14211http://downloads.avaya.com/css/P8/documents/100133195http://support.avaya.com/css/P8/documents/100128655http://www.mandriva.com/security/advisories?name=MDVSA-2011:041http://www.mozilla.org/security/announce/2011/mfsa2011-02.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0312.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0313.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=616659https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14211
2011-03-02
Published