CVE-2011-0058
published 2011-03-02CVE-2011-0058: Buffer overflow in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, on Windows allows remote attackers to execute arbitrary…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.50%
91.9th percentile
Buffer overflow in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a long string that triggers construction of a long text run.
Affected
143 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.5.16 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Xulrunner vulnerabilities
vendor_ubuntu·2011-04-30
CVE-2011-0077 Xulrunner vulnerabilities
Title: Xulrunner vulnerabilities
Summary: Multiple xulrunner-1.9.1 vulnerabilities
A large number of security issues were discovered in the Gecko rendering
engine. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: After a standard system update you need to restart any applications which
use Xulrunner to make all the necessary changes.
Ubuntu
Firefox and Xulrunner regression
vendor_ubuntu·2011-03-07·CVSS 6.8
[MEDIUM] Firefox and Xulrunner regression
Title: Firefox and Xulrunner regression
Summary: Fixed Java applet regression introduced in the update for USN 1049-1
USN-1049-1 fixed vulnerabilities in Firefox and Xulrunner. That update
introduced a regression where some Java applets would fail to load. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Jesse Ruderman, Igor Bukanov, Olli Pettay, Gary Kwong, Jeff Walden, Henry
Sivonen, Martijn Wargers, David Baron and Marcia Knous discovered several
memory issues in the browser engine. An attacker could exploit these to
crash the browser or possibly run arbitrary code as the user invoking the
program. (CVE-2011-0053, CVE-2011-0062)
Zach Hoffman discovered that a recursive call to eval() wrapped in a
try/catch statement places the browser i
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2011-03-03·CVSS 9.3
CVE-2011-0053 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Multiple browser flaws
Jesse Ruderman, Igor Bukanov, Olli Pettay, Gary Kwong, Jeff Walden, Henry
Sivonen, Martijn Wargers, David Baron and Marcia Knous discovered several
memory issues in the browser engine. An attacker could exploit these to
crash the browser or possibly run arbitrary code as the user invoking the
program. (CVE-2011-0053, CVE-2011-0062)
Zach Hoffman discovered that a recursive call to eval() wrapped in a
try/catch statement places the browser into a inconsistent state. An
attacker could exploit this to force a user to accept any dialog.
(CVE-2011-0051)
It was discovered that memory was used after being freed in a method used
by JSON.stringify. An attacker could exploit this to crash the browser or
possibly run arbi
Red Hat
Mozilla memory corruption during text run construction (MFSA 2011-07)
vendor_redhat·2011-03-01·CVSS 10.0
CVE-2011-0058 [CRITICAL] Mozilla memory corruption during text run construction (MFSA 2011-07)
Mozilla memory corruption during text run construction (MFSA 2011-07)
Buffer overflow in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a long string that triggers construction of a long text run.
Package: firefox (Red Hat Enterprise Linux Extended Update Support 4.8) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 5.6) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 6.0) - Affected
GHSA
GHSA-m728-52w7-3gvf: Buffer overflow in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-03
CVE-2011-0058 [HIGH] CWE-119 GHSA-m728-52w7-3gvf: Buffer overflow in Mozilla Firefox before 3
Buffer overflow in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a long string that triggers construction of a long text run.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4609 glibc: svc_run() produces high cpu usage when accept() fails with EMFILE error
bugzilla·2011-12-13·CVSS 5.0
CVE-2011-4609 [MEDIUM] CVE-2011-4609 glibc: svc_run() produces high cpu usage when accept() fails with EMFILE error
CVE-2011-4609 glibc: svc_run() produces high cpu usage when accept() fails with EMFILE error
It was reported that if a process that called glibc's svc_run() exceeded the limit of opened files for a longer period of time, that accept() in rendezvous_request()/svcudp_recv() would fail with the EMFILE error, which would lead to looping between poll(), accept(), and 'for' loops which would consume a lot of CPU time. This could lead to an unresponsive system that requires human intervention (service restart or system restart) to resolve.
Discussion:
Created attachment 546362
patch to correct the flaw
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2012:0058 https://rhn.redhat.com/errata/RHSA-2012-0058.html
---
This issue has been addressed i
Bugzilla
CVE-2011-0058 Mozilla memory corruption during text run construction (MFSA 2011-07)
bugzilla·2011-02-04·CVSS 10.0
CVE-2011-0058 [CRITICAL] CVE-2011-0058 Mozilla memory corruption during text run construction (MFSA 2011-07)
CVE-2011-0058 Mozilla memory corruption during text run construction (MFSA 2011-07)
Alex Miller reported that when very long strings were constructed
and inserted into an HTML document, the browser would incorrectly
construct the layout objects used to display the text.
Under such conditions an incorrect length would be calculated for
a text run resulting in too small of a memory buffer being allocated
to store the text.
This issue could be used by an attacker to write data past the end
of the buffer and execute malicious code on a victim's computer.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-07.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Vi
http://downloads.avaya.com/css/P8/documents/100133195http://www.mandriva.com/security/advisories?name=MDVSA-2011:041http://www.mozilla.org/security/announce/2011/mfsa2011-07.htmlhttp://www.securityfocus.com/bid/46660https://bugzilla.mozilla.org/show_bug.cgi?id=607160https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14254http://downloads.avaya.com/css/P8/documents/100133195http://www.mandriva.com/security/advisories?name=MDVSA-2011:041http://www.mozilla.org/security/announce/2011/mfsa2011-07.htmlhttp://www.securityfocus.com/bid/46660https://bugzilla.mozilla.org/show_bug.cgi?id=607160https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14254
2011-03-02
Published