CVE-2011-0071Path Traversal in Mozilla Firefox

CWE-22Path Traversal10 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
1.7%
top 17.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 7
Latest updateMay 17

Description

Directory traversal vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 on Windows allows remote attackers to determine the existence of arbitrary files, and possibly load resources, via vectors involving a resource: URL.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/firefox3.5.18+102
NVDmozilla/seamonkey2.0.13+46
NVDmozilla/thunderbird3.1.9+81

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2mm2-3xh2-c3hj: Directory traversal vulnerability in Mozilla Firefox before 32022-05-17
CVEList
CVE-2011-0071: Directory traversal vulnerability in Mozilla Firefox before 32011-05-07

📋Vendor Advisories

6
Ubuntu
Thunderbird regression2011-06-06
Ubuntu
Thunderbird vulnerabilities2011-05-05
Ubuntu
Thunderbird vulnerabilities2011-05-05
Ubuntu
Xulrunner vulnerabilities2011-04-30
Ubuntu
Firefox and Xulrunner vulnerabilities2011-04-29

💬Community

1
Bugzilla
CVE-2011-0071 Mozilla directory traversal via resource protocol (MFSA 2011-16)2011-04-28
CVE-2011-0071 — Path Traversal in Mozilla Firefox | cvebase