CVE-2011-0061
published 2011-03-02CVE-2011-0061: Buffer overflow in Mozilla Firefox 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 might allow remote attackers to execute arbitrary…
PriorityP339critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.70%
90.8th percentile
Buffer overflow in Mozilla Firefox 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.
Affected
137 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 2.0.11 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and Xulrunner regression
vendor_ubuntu·2011-03-07·CVSS 6.8
[MEDIUM] Firefox and Xulrunner regression
Title: Firefox and Xulrunner regression
Summary: Fixed Java applet regression introduced in the update for USN 1049-1
USN-1049-1 fixed vulnerabilities in Firefox and Xulrunner. That update
introduced a regression where some Java applets would fail to load. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Jesse Ruderman, Igor Bukanov, Olli Pettay, Gary Kwong, Jeff Walden, Henry
Sivonen, Martijn Wargers, David Baron and Marcia Knous discovered several
memory issues in the browser engine. An attacker could exploit these to
crash the browser or possibly run arbitrary code as the user invoking the
program. (CVE-2011-0053, CVE-2011-0062)
Zach Hoffman discovered that a recursive call to eval() wrapped in a
try/catch statement places the browser i
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2011-03-03·CVSS 9.3
CVE-2011-0061 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird could be made to crash or run programs as your login if it
opened specially crafted mail.
Jesse Ruderman, Igor Bukanov, Olli Pettay, Gary Kwong, Jeff Walden, Henry
Sivonen, Martijn Wargers, David Baron and Marcia Knous discovered several
memory issues in the browser engine. An attacker could exploit these to
crash the browser or possibly run arbitrary code as the user invoking the
program. (CVE-2011-0053, CVE-2011-0062)
Roberto Suggi Liverani discovered a possible issue with unsafe JavaScript
execution in chrome documents. A malicious extension could exploit this to
execute arbitrary code with chrome privlieges. (CVE-2010-1585)
Jordi Chancel discovered a buffer overlow in the JPEG decoding engine. An
attacker could exploit this to
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2011-03-03·CVSS 9.3
CVE-2011-0053 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Multiple browser flaws
Jesse Ruderman, Igor Bukanov, Olli Pettay, Gary Kwong, Jeff Walden, Henry
Sivonen, Martijn Wargers, David Baron and Marcia Knous discovered several
memory issues in the browser engine. An attacker could exploit these to
crash the browser or possibly run arbitrary code as the user invoking the
program. (CVE-2011-0053, CVE-2011-0062)
Zach Hoffman discovered that a recursive call to eval() wrapped in a
try/catch statement places the browser into a inconsistent state. An
attacker could exploit this to force a user to accept any dialog.
(CVE-2011-0051)
It was discovered that memory was used after being freed in a method used
by JSON.stringify. An attacker could exploit this to crash the browser or
possibly run arbi
Red Hat
Mozilla crash caused by corrupted JPEG image (MFSA 2011-09)
vendor_redhat·2011-03-01·CVSS 9.3
CVE-2011-0061 [CRITICAL] Mozilla crash caused by corrupted JPEG image (MFSA 2011-09)
Mozilla crash caused by corrupted JPEG image (MFSA 2011-09)
Buffer overflow in Mozilla Firefox 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.
Package: firefox (Red Hat Enterprise Linux Extended Update Support 4.8) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 5.6) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 6.0) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update Support 6.0) - Affected
GHSA
GHSA-7m27-7836-w9w2: Buffer overflow in Mozilla Firefox 3
ghsa_unreviewed·2022-05-03
CVE-2011-0061 [HIGH] CWE-119 GHSA-7m27-7836-w9w2: Buffer overflow in Mozilla Firefox 3
Buffer overflow in Mozilla Firefox 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.
No detection rules found.
No public exploits indexed.
http://downloads.avaya.com/css/P8/documents/100133195http://www.mandriva.com/security/advisories?name=MDVSA-2011:041http://www.mandriva.com/security/advisories?name=MDVSA-2011:042http://www.mozilla.org/security/announce/2011/mfsa2011-09.htmlhttp://www.securityfocus.com/bid/46651https://bugzilla.mozilla.org/show_bug.cgi?id=610601https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14486http://downloads.avaya.com/css/P8/documents/100133195http://www.mandriva.com/security/advisories?name=MDVSA-2011:041http://www.mandriva.com/security/advisories?name=MDVSA-2011:042http://www.mozilla.org/security/announce/2011/mfsa2011-09.htmlhttp://www.securityfocus.com/bid/46651https://bugzilla.mozilla.org/show_bug.cgi?id=610601https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14486
2011-03-02
Published