CVE-2011-2986
published 2011-08-18CVE-2011-2986: Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used on Windows…
PriorityP422medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.20%
64.9th percentile
Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used on Windows, allows remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas.
Affected
132 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w28f-6ggv-2vjv: Mozilla Firefox 4
ghsa_unreviewed·2022-05-17
CVE-2011-2986 [MEDIUM] CWE-200 GHSA-w28f-6ggv-2vjv: Mozilla Firefox 4
Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used on Windows, allows remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas.
GHSA
GHSA-rpwr-6r9c-47vr: Mozilla Firefox 7
ghsa_unreviewed·2022-05-17·CVSS 5.0
CVE-2011-3649 [MEDIUM] CWE-200 GHSA-rpwr-6r9c-47vr: Mozilla Firefox 7
Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas. NOTE: this issue exists because of a CVE-2011-2986 regression.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00023.htmlhttp://secunia.com/advisories/49055http://www.mozilla.org/security/announce/2011/mfsa2011-29.htmlhttp://www.mozilla.org/security/announce/2011/mfsa2011-31.htmlhttp://www.mozilla.org/security/announce/2011/mfsa2011-33.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=655836https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14497http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00023.htmlhttp://secunia.com/advisories/49055http://www.mozilla.org/security/announce/2011/mfsa2011-29.htmlhttp://www.mozilla.org/security/announce/2011/mfsa2011-31.htmlhttp://www.mozilla.org/security/announce/2011/mfsa2011-33.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=655836https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14497
2011-08-18
Published