CVE-2011-2983
published 2011-08-18CVE-2011-2983: Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and possibly other products does not properly handle the…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.58%
72.7th percentile
Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and possibly other products does not properly handle the RegExp.input property, which allows remote attackers to bypass the Same Origin Policy and read data from a different domain via a crafted web site, possibly related to a use-after-free.
Affected
219 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.6.19 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2011-08-26·CVSS 10.0
CVE-2011-0084 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Multiple vulnerabilities have been fixed in Thunderbird.
Gary Kwong, Igor Bukanov, and Bob Clary discovered multiple memory
vulnerabilities in the Gecko rendering engine. An attacker could use
these to possibly execute arbitrary code with the privileges of the user
invoking Thunderbird. (CVE-2011-2982)
It was discovered that a vulnerability in event management code could
permit JavaScript to be run in the wrong context. This could potentially
allow a malicious website to run code as another website or with escalated
privileges in a chrome-privileged context. (CVE-2011-2981)
It was discovered that an SVG text manipulation routine contained a
dangling pointer vulnerability. An attacker could potentially use this to
crash Thunderbird or execute
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2011-08-19·CVSS 10.0
CVE-2011-2982 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Multiple vulnerabilities have been fixed in Firefox and Xulrunner.
Gary Kwong, Igor Bukanov, and Bob Clary discovered multiple memory
vulnerabilities in the browser rendering engine. An attacker could use
these to possibly execute arbitrary code with the privileges of the user
invoking Firefox. (CVE-2011-2982)
It was discovered that a vulnerability in event management code could
permit JavaScript to be run in the wrong context. This could potentially
allow a malicious website to run code as another website or with escalated
privileges within the browser. (CVE-2011-2981)
It was discovered that an SVG text manipulation routine contained a
dangling pointer vulnerability. An attacker could potentially use this to
crash Firefox or execut
Red Hat
Mozilla: Private data leakage using RegExp.input
vendor_redhat·2011-08-16·CVSS 4.3
CVE-2011-2983 [MEDIUM] Mozilla: Private data leakage using RegExp.input
Mozilla: Private data leakage using RegExp.input
Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and possibly other products does not properly handle the RegExp.input property, which allows remote attackers to bypass the Same Origin Policy and read data from a different domain via a crafted web site, possibly related to a use-after-free.
Package: firefox (Red Hat Enterprise Linux Extended Update Support 5.7) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update Support 5.7) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 6.1) - Affected
GHSA
GHSA-wmwp-4vqm-9jhc: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-17
CVE-2011-2983 [MEDIUM] CWE-200 GHSA-wmwp-4vqm-9jhc: Mozilla Firefox before 3
Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and possibly other products does not properly handle the RegExp.input property, which allows remote attackers to bypass the Same Origin Policy and read data from a different domain via a crafted web site, possibly related to a use-after-free.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-08/msg00027.htmlhttp://www.debian.org/security/2011/dsa-2295http://www.debian.org/security/2011/dsa-2296http://www.debian.org/security/2011/dsa-2297http://www.mandriva.com/security/advisories?name=MDVSA-2011:127http://www.mozilla.org/security/announce/2011/mfsa2011-30.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1164.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1165.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1167.htmlhttp://www.securitytracker.com/id?1025940https://bugzilla.mozilla.org/show_bug.cgi?id=626297https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14272http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-08/msg00027.htmlhttp://www.debian.org/security/2011/dsa-2295http://www.debian.org/security/2011/dsa-2296http://www.debian.org/security/2011/dsa-2297http://www.mandriva.com/security/advisories?name=MDVSA-2011:127http://www.mozilla.org/security/announce/2011/mfsa2011-30.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1164.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1165.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1167.htmlhttp://www.securitytracker.com/id?1025940https://bugzilla.mozilla.org/show_bug.cgi?id=626297https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14272
2011-08-18
Published