CVE-2011-0080
published 2011-05-07CVE-2011-0080: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and…
PriorityP336critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.50%
92.0th percentile
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Affected
151 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird regression
vendor_ubuntu·2011-06-06·CVSS 10.0
[CRITICAL] Thunderbird regression
Title: Thunderbird regression
Summary: An empty menu bar sometimes appeared after upgrade in USN-1122-2
USN-1122-2 fixed vulnerabilities in Thunderbird on Ubuntu 11.04. A
regression was introduced which caused Thunderbird to display an empty menu
bar. This update fixes the problem. We apologize for the inconvenience.
Original advisory details:
It was discovered that there was a vulnerability in the memory handling of
certain types of content. An attacker could exploit this to possibly run
arbitrary code as the user running Thunderbird. (CVE-2011-0081)
It was discovered that Thunderbird incorrectly handled certain JavaScript
requests. If JavaScript were enabled, an attacker could exploit this to
possibly run arbitrary code as the user running Thunderbird.
(CVE-2011-0069)
Ian Beer disc
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2011-05-05·CVSS 10.0
CVE-2011-0065 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird could be made to run programs as your login if it opened
specially crafted mail.
It was discovered that there was a vulnerability in the memory handling of
certain types of content. An attacker could exploit this to possibly run
arbitrary code as the user running Thunderbird. (CVE-2011-0081)
It was discovered that Thunderbird incorrectly handled certain JavaScript
requests. If JavaScript were enabled, an attacker could exploit this to
possibly run arbitrary code as the user running Thunderbird.
(CVE-2011-0069)
Ian Beer discovered a vulnerability in the memory handling of a certain
types of documents. An attacker could exploit this to possibly run
arbitrary code as the user running Thunderbird. (CVE-2011-0070)
Bob Clary, Henri Siv
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2011-05-05·CVSS 10.0
CVE-2011-0065 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird could be made to run programs as your login if it opened
specially crafted mail.
USN-1122-1 fixed vulnerabilities in Thunderbird for Lucid and Maverick.
This update provides the corresponding fixes for Natty.
Original advisory details:
It was discovered that there was a vulnerability in the memory handling of
certain types of content. An attacker could exploit this to possibly run
arbitrary code as the user running Thunderbird. (CVE-2011-0081)
It was discovered that Thunderbird incorrectly handled certain JavaScript
requests. If JavaScript were enabled, an attacker could exploit this to
possibly run arbitrary code as the user running Thunderbird.
(CVE-2011-0069)
Ian Beer discovered a vulnerability in the memory handling of a cer
Ubuntu
Xulrunner vulnerabilities
vendor_ubuntu·2011-04-30
CVE-2011-0077 Xulrunner vulnerabilities
Title: Xulrunner vulnerabilities
Summary: Multiple xulrunner-1.9.1 vulnerabilities
A large number of security issues were discovered in the Gecko rendering
engine. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: After a standard system update you need to restart any applications which
use Xulrunner to make all the necessary changes.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2011-04-29·CVSS 10.0
CVE-2011-0081 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Multiple vulnerabilities in Firefox and Xulrunner
It was discovered that there was a vulnerability in the memory handling of
certain types of content. An attacker could exploit this to possibly run
arbitrary code as the user running Firefox. (CVE-2011-0081)
It was discovered that Firefox incorrectly handled certain JavaScript
requests. An attacker could exploit this to possibly run arbitrary code as
the user running Firefox. (CVE-2011-0069)
Ian Beer discovered a vulnerability in the memory handling of a certain
types of documents. An attacker could exploit this to possibly run
arbitrary code as the user running Firefox. (CVE-2011-0070)
Bob Clary, Henri Sivonen, Marco Bonardo, Mats Palmgren and Jesse Ruderman
discovered several memo
Red Hat
Mozilla memory safety issue (MFSA 2011-12)
vendor_redhat·2011-04-28·CVSS 10.0
CVE-2011-0080 [CRITICAL] Mozilla memory safety issue (MFSA 2011-12)
Mozilla memory safety issue (MFSA 2011-12)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
GHSA
GHSA-j2f3-jrwf-748f: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3
ghsa_unreviewed·2022-05-17
CVE-2011-0080 [HIGH] GHSA-j2f3-jrwf-748f: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3659 Mozilla: child nodes from nsDOMAttribute still accessible after removal of nodes (MFSA 2012-04)
bugzilla·2012-01-31·CVSS 9.3
CVE-2011-3659 [CRITICAL] CVE-2011-3659 Mozilla: child nodes from nsDOMAttribute still accessible after removal of nodes (MFSA 2012-04)
CVE-2011-3659 Mozilla: child nodes from nsDOMAttribute still accessible after removal of nodes (MFSA 2012-04)
It was found that removed child nodes of nsDOMAttribute could be accessed under certain circumstances, due to premature notification of AttributeChildRemoved. This use-after-free of the child nodes could possibly allow for the the remote execution of arbitrary code.
Reference:
https://bugzilla.mozilla.org/show_bug.cgi?id=708198
External References:
http://www.mozilla.org/security/announce/2012/mfsa2012-04.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2012:0080 https://rhn.redhat.com/errata/RHSA-2012-0080.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise L
Bugzilla
CVE-2011-0080 Mozilla memory safety issue (MFSA 2011-12)
bugzilla·2011-04-29·CVSS 10.0
CVE-2011-0080 [CRITICAL] CVE-2011-0080 Mozilla memory safety issue (MFSA 2011-12)
CVE-2011-0080 Mozilla memory safety issue (MFSA 2011-12)
Mozilla developers identified and fixed several memory safety bugs in the
browser engine used in Firefox and other Mozilla-based products. Some of
these bugs showed evidence of memory corruption under certain
circumstances, and we presume that with enough effort at least some of
these could be exploited to run arbitrary code.
Mozilla developers Bob Clary, Henri Sivonen, Marco Bonardo, Mats Palmgren
and Jesse Ruderman reported memory safety issues which affected Firefox 3.6
and Firefox 3.5
Discussion:
This is public via:
http://www.mozilla.org/security/announce/2011/mfsa2011-12.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Via RHSA-2011:0473 https://rhn.redhat.com/errata/RHSA-2011-04
http://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_thunderbirdhttp://downloads.avaya.com/css/P8/documents/100134543http://downloads.avaya.com/css/P8/documents/100144158http://www.debian.org/security/2011/dsa-2227http://www.debian.org/security/2011/dsa-2228http://www.debian.org/security/2011/dsa-2235http://www.mandriva.com/security/advisories?name=MDVSA-2011:079http://www.mandriva.com/security/advisories?name=MDVSA-2011:080http://www.mozilla.org/security/announce/2011/mfsa2011-12.htmlhttp://www.securityfocus.com/bid/47641https://bugzilla.mozilla.org/show_bug.cgi?id=615147https://bugzilla.mozilla.org/show_bug.cgi?id=634257https://bugzilla.mozilla.org/show_bug.cgi?id=637621https://bugzilla.mozilla.org/show_bug.cgi?id=637957https://bugzilla.mozilla.org/show_bug.cgi?id=638236https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13866http://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_thunderbirdhttp://downloads.avaya.com/css/P8/documents/100134543http://downloads.avaya.com/css/P8/documents/100144158http://www.debian.org/security/2011/dsa-2227http://www.debian.org/security/2011/dsa-2228http://www.debian.org/security/2011/dsa-2235http://www.mandriva.com/security/advisories?name=MDVSA-2011:079http://www.mandriva.com/security/advisories?name=MDVSA-2011:080http://www.mozilla.org/security/announce/2011/mfsa2011-12.htmlhttp://www.securityfocus.com/bid/47641https://bugzilla.mozilla.org/show_bug.cgi?id=615147https://bugzilla.mozilla.org/show_bug.cgi?id=634257https://bugzilla.mozilla.org/show_bug.cgi?id=637621https://bugzilla.mozilla.org/show_bug.cgi?id=637957https://bugzilla.mozilla.org/show_bug.cgi?id=638236https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13866
2011-05-07
Published