cbcvebase.
CVE-2011-2988
published 2011-08-18

CVE-2011-2988: Buffer overflow in an unspecified string class in the WebGL shader implementation in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before…

PriorityP339critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.49%
91.9th percentile
Buffer overflow in an unspecified string class in the WebGL shader implementation in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long source-code block for a shader.

Affected

21 ranges
VendorProductVersion rangeFixed in
mozillafirefox
mozillafirefox
mozillafirefox
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillathunderbird<= 5.0

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.