CVE-2011-2996Out-of-bounds Write in Mozilla Firefox

6 documents5 sources
Severity
10.0CRITICALNVD
EPSS
8.7%
top 7.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 29
Latest updateMay 17

Description

Unspecified vulnerability in the plugin API in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDmozilla/firefox21 versions+20

🔴Vulnerability Details

1
GHSA
GHSA-838w-vrg2-2x7q: Unspecified vulnerability in the plugin API in Mozilla Firefox 32022-05-17

📋Vendor Advisories

3
Ubuntu
Firefox and Xulrunner vulnerabilities2011-09-28
Ubuntu
Thunderbird vulnerabilities2011-09-28
Red Hat
Mozilla: crash in plugin API (MFSA 2011-36)2011-09-28

💬Community

1
Bugzilla
CVE-2011-2996 Mozilla: crash in plugin API (MFSA 2011-36)2011-09-28