CVE-2011-0078
published 2011-05-07CVE-2011-0078: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before…
PriorityP335critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.26%
91.6th percentile
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0075, and CVE-2011-0077.
Affected
151 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird regression
vendor_ubuntu·2011-06-06·CVSS 10.0
[CRITICAL] Thunderbird regression
Title: Thunderbird regression
Summary: An empty menu bar sometimes appeared after upgrade in USN-1122-2
USN-1122-2 fixed vulnerabilities in Thunderbird on Ubuntu 11.04. A
regression was introduced which caused Thunderbird to display an empty menu
bar. This update fixes the problem. We apologize for the inconvenience.
Original advisory details:
It was discovered that there was a vulnerability in the memory handling of
certain types of content. An attacker could exploit this to possibly run
arbitrary code as the user running Thunderbird. (CVE-2011-0081)
It was discovered that Thunderbird incorrectly handled certain JavaScript
requests. If JavaScript were enabled, an attacker could exploit this to
possibly run arbitrary code as the user running Thunderbird.
(CVE-2011-0069)
Ian Beer disc
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2011-05-05·CVSS 10.0
CVE-2011-0065 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird could be made to run programs as your login if it opened
specially crafted mail.
It was discovered that there was a vulnerability in the memory handling of
certain types of content. An attacker could exploit this to possibly run
arbitrary code as the user running Thunderbird. (CVE-2011-0081)
It was discovered that Thunderbird incorrectly handled certain JavaScript
requests. If JavaScript were enabled, an attacker could exploit this to
possibly run arbitrary code as the user running Thunderbird.
(CVE-2011-0069)
Ian Beer discovered a vulnerability in the memory handling of a certain
types of documents. An attacker could exploit this to possibly run
arbitrary code as the user running Thunderbird. (CVE-2011-0070)
Bob Clary, Henri Siv
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2011-05-05·CVSS 10.0
CVE-2011-0065 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird could be made to run programs as your login if it opened
specially crafted mail.
USN-1122-1 fixed vulnerabilities in Thunderbird for Lucid and Maverick.
This update provides the corresponding fixes for Natty.
Original advisory details:
It was discovered that there was a vulnerability in the memory handling of
certain types of content. An attacker could exploit this to possibly run
arbitrary code as the user running Thunderbird. (CVE-2011-0081)
It was discovered that Thunderbird incorrectly handled certain JavaScript
requests. If JavaScript were enabled, an attacker could exploit this to
possibly run arbitrary code as the user running Thunderbird.
(CVE-2011-0069)
Ian Beer discovered a vulnerability in the memory handling of a cer
Ubuntu
Xulrunner vulnerabilities
vendor_ubuntu·2011-04-30
CVE-2011-0077 Xulrunner vulnerabilities
Title: Xulrunner vulnerabilities
Summary: Multiple xulrunner-1.9.1 vulnerabilities
A large number of security issues were discovered in the Gecko rendering
engine. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: After a standard system update you need to restart any applications which
use Xulrunner to make all the necessary changes.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2011-04-29·CVSS 10.0
CVE-2011-0081 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Multiple vulnerabilities in Firefox and Xulrunner
It was discovered that there was a vulnerability in the memory handling of
certain types of content. An attacker could exploit this to possibly run
arbitrary code as the user running Firefox. (CVE-2011-0081)
It was discovered that Firefox incorrectly handled certain JavaScript
requests. An attacker could exploit this to possibly run arbitrary code as
the user running Firefox. (CVE-2011-0069)
Ian Beer discovered a vulnerability in the memory handling of a certain
types of documents. An attacker could exploit this to possibly run
arbitrary code as the user running Firefox. (CVE-2011-0070)
Bob Clary, Henri Sivonen, Marco Bonardo, Mats Palmgren and Jesse Ruderman
discovered several memo
Red Hat
Mozilla crash from bad iframe source (MFSA 2011-12)
vendor_redhat·2011-04-28·CVSS 10.0
CVE-2011-0075 [CRITICAL] Mozilla crash from bad iframe source (MFSA 2011-12)
Mozilla crash from bad iframe source (MFSA 2011-12)
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0077, and CVE-2011-0078.
Red Hat
Mozilla integer overflow in frameset spec (MFSA 2011-12)
vendor_redhat·2011-04-28·CVSS 10.0
CVE-2011-0077 [CRITICAL] CWE-190 Mozilla integer overflow in frameset spec (MFSA 2011-12)
Mozilla integer overflow in frameset spec (MFSA 2011-12)
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0075, and CVE-2011-0078.
Red Hat
Mozilla OOM condition arbitrary memory write (MFSA 2011-12)
vendor_redhat·2011-04-28·CVSS 10.0
CVE-2011-0078 [CRITICAL] Mozilla OOM condition arbitrary memory write (MFSA 2011-12)
Mozilla OOM condition arbitrary memory write (MFSA 2011-12)
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0075, and CVE-2011-0077.
Red Hat
Mozilla crash from several marquee elements (MFSA 2011-12)
vendor_redhat·2011-04-28·CVSS 10.0
CVE-2011-0074 [CRITICAL] Mozilla crash from several marquee elements (MFSA 2011-12)
Mozilla crash from several marquee elements (MFSA 2011-12)
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0075, CVE-2011-0077, and CVE-2011-0078.
Red Hat
Mozilla use after free flaw (MFSA 2011-12)
vendor_redhat·2011-04-28·CVSS 10.0
CVE-2011-0072 [CRITICAL] CWE-416 Mozilla use after free flaw (MFSA 2011-12)
Mozilla use after free flaw (MFSA 2011-12)
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0074, CVE-2011-0075, CVE-2011-0077, and CVE-2011-0078.
GHSA
GHSA-8r4w-5q86-x94x: Unspecified vulnerability in the browser engine in Mozilla Firefox 3
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2011-0077 [CRITICAL] GHSA-8r4w-5q86-x94x: Unspecified vulnerability in the browser engine in Mozilla Firefox 3
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0075, and CVE-2011-0078.
GHSA
GHSA-87rh-32pw-rjhp: Unspecified vulnerability in the browser engine in Mozilla Firefox 3
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2011-0072 [CRITICAL] GHSA-87rh-32pw-rjhp: Unspecified vulnerability in the browser engine in Mozilla Firefox 3
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0074, CVE-2011-0075, CVE-2011-0077, and CVE-2011-0078.
GHSA
GHSA-mgrr-r765-32qh: Unspecified vulnerability in the browser engine in Mozilla Firefox 3
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2011-0075 [CRITICAL] GHSA-mgrr-r765-32qh: Unspecified vulnerability in the browser engine in Mozilla Firefox 3
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0077, and CVE-2011-0078.
GHSA
GHSA-mhg3-gghc-44m4: Unspecified vulnerability in the browser engine in Mozilla Firefox 3
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2011-0078 [CRITICAL] GHSA-mhg3-gghc-44m4: Unspecified vulnerability in the browser engine in Mozilla Firefox 3
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0075, and CVE-2011-0077.
GHSA
GHSA-rrhh-jw72-ccc9: Unspecified vulnerability in the browser engine in Mozilla Firefox 3
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2011-0074 [CRITICAL] GHSA-rrhh-jw72-ccc9: Unspecified vulnerability in the browser engine in Mozilla Firefox 3
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0075, CVE-2011-0077, and CVE-2011-0078.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4610 JBoss Web remote denial of service when surrogate pair character is placed at buffer boundary
bugzilla·2011-12-15·CVSS 5.0
CVE-2011-4610 [MEDIUM] CVE-2011-4610 JBoss Web remote denial of service when surrogate pair character is placed at buffer boundary
CVE-2011-4610 JBoss Web remote denial of service when surrogate pair character is placed at buffer boundary
JBoss Web will enter into an infinite loop when a surrogate pair character is placed at the boundary of an internal buffer. A remote attacker could exploit this flaw to trigger a denial-of-service attack against a JBoss Web server that is hosting applications with UTF-8 character encoding enabled, or that will include user-supplied UTF-8 strings in a response.
Discussion:
Acknowledgements:
Red Hat would like to thank NTT OSSC for reporting this issue.
---
This issue has been addressed in following products:
JBoss Communications Platform 5.1.3
Via RHSA-2012:0078 https://rhn.redhat.com/errata/RHSA-2012-0078.html
---
This issue has been addressed in following products:
JBoss
Bugzilla
CVE-2011-0078 Mozilla OOM condition arbitrary memory write (MFSA 2011-12)
bugzilla·2011-04-28·CVSS 10.0
CVE-2011-0078 [CRITICAL] CVE-2011-0078 Mozilla OOM condition arbitrary memory write (MFSA 2011-12)
CVE-2011-0078 Mozilla OOM condition arbitrary memory write (MFSA 2011-12)
An arbitrary memory write flaw was found in the way Mozilla products deal
with an out of memory (OOM) condition. If all memory is consumed, it is
possible for arbitrary data to written using array offsets.
Discussion:
This is public via:
http://www.mozilla.org/security/announce/2011/mfsa2011-12.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Via RHSA-2011:0473 https://rhn.redhat.com/errata/RHSA-2011-0473.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0475 https://rhn.redhat.com/errata/RHSA-2011-0475.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise L
http://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_thunderbirdhttp://downloads.avaya.com/css/P8/documents/100134543http://downloads.avaya.com/css/P8/documents/100144158http://www.debian.org/security/2011/dsa-2227http://www.debian.org/security/2011/dsa-2228http://www.debian.org/security/2011/dsa-2235http://www.mandriva.com/security/advisories?name=MDVSA-2011:079http://www.mandriva.com/security/advisories?name=MDVSA-2011:080http://www.mozilla.org/security/announce/2011/mfsa2011-12.htmlhttp://www.securityfocus.com/bid/47651https://bugzilla.mozilla.org/show_bug.cgi?id=635705https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14246http://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_thunderbirdhttp://downloads.avaya.com/css/P8/documents/100134543http://downloads.avaya.com/css/P8/documents/100144158http://www.debian.org/security/2011/dsa-2227http://www.debian.org/security/2011/dsa-2228http://www.debian.org/security/2011/dsa-2235http://www.mandriva.com/security/advisories?name=MDVSA-2011:079http://www.mandriva.com/security/advisories?name=MDVSA-2011:080http://www.mozilla.org/security/announce/2011/mfsa2011-12.htmlhttp://www.securityfocus.com/bid/47651https://bugzilla.mozilla.org/show_bug.cgi?id=635705https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14246
2011-05-07
Published