CVE-2011-2368Mozilla Firefox vulnerability

CWE-2645 documents3 sources
Severity
10.0CRITICALNVD
EPSS
4.6%
top 10.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 30
Latest updateMay 17

Description

The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict write operations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDmozilla/firefox4.0, 4.0.1+1

🔴Vulnerability Details

1
GHSA
GHSA-7g8x-jvgq-fx72: The WebGL implementation in Mozilla Firefox 42022-05-17

📋Vendor Advisories

3
Ubuntu
Firefox regression2011-06-23
Ubuntu
mozvoikko, ubufox, webfav update2011-06-22
Ubuntu
Firefox vulnerabilities2011-06-22