CVE-2011-2370Mozilla Firefox vulnerability

CWE-2646 documents4 sources
Severity
5.0MEDIUMNVD
EPSS
0.3%
top 45.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 30
Latest updateMay 17

Description

Mozilla Firefox before 5.0 does not properly enforce the whitelist for the xpinstall functionality, which allows remote attackers to trigger an installation dialog for a (1) add-on or (2) theme via unspecified vectors.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/firefox4.0.1+106

🔴Vulnerability Details

1
GHSA
GHSA-q4f3-7m9m-fpqf: Mozilla Firefox before 52022-05-17

📋Vendor Advisories

3
Ubuntu
Firefox regression2011-06-23
Ubuntu
mozvoikko, ubufox, webfav update2011-06-22
Ubuntu
Firefox vulnerabilities2011-06-22

💬Community

1
Bugzilla
CVE-2011-4362 lighttpd: Out of bounds read due to a signedness error (DoS, crash)2011-11-30