CVE-2011-2367Mozilla Firefox vulnerability

CWE-2645 documents3 sources
Severity
6.4MEDIUMNVD
EPSS
0.7%
top 28.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 30
Latest updateMay 17

Description

The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sensitive information from GPU memory associated with an arbitrary process, or cause a denial of service (application crash), via unspecified vectors.

CVSS vector

AV:N/AC:L/C:P/I:N/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages1 packages

NVDmozilla/firefox4.0, 4.0.1+1

🔴Vulnerability Details

1
GHSA
GHSA-m3v7-47jg-qghf: The WebGL implementation in Mozilla Firefox 42022-05-17

📋Vendor Advisories

3
Ubuntu
Firefox regression2011-06-23
Ubuntu
mozvoikko, ubufox, webfav update2011-06-22
Ubuntu
Firefox vulnerabilities2011-06-22