CVE-2011-2377Improper Restriction of Operations within the Bounds of a Memory Buffer in Mozilla Firefox

Severity
5.0MEDIUMNVD
EPSS
5.9%
top 9.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 30
Latest updateMay 17

Description

Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace image.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/firefox3.6.17+106
NVDmozilla/thunderbird3.1.10+82
NVDmozilla/seamonkey48 versions+47

🔴Vulnerability Details

2
GHSA
GHSA-v2pm-qf2g-3x86: Mozilla Firefox before 32022-05-17
CVEList
CVE-2011-2377: Mozilla Firefox before 32011-06-30

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2011-07-15
Ubuntu
Firefox regression2011-06-29
Ubuntu
Firefox regression2011-06-23
Ubuntu
Firefox and Xulrunner vulnerabilities2011-06-22
Ubuntu
mozvoikko, ubufox, webfav update2011-06-22

💬Community

1
Bugzilla
CVE-2011-2377 Mozilla Crash caused by corrupted JPEG image (MFSA 2011-21)2011-06-21
CVE-2011-2377 — Mozilla Firefox vulnerability | cvebase