CVE-2011-2998
published 2011-09-30CVE-2011-2998: Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary…
PriorityP339critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.37%
91.8th percentile
Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via JavaScript code containing a large RegExp expression.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Integer underflow when using JavaScript RegExp (MFSA 2011-37)
vendor_redhat·2011-09-28·CVSS 10.0
CVE-2011-2998 [CRITICAL] CWE-190 Mozilla: Integer underflow when using JavaScript RegExp (MFSA 2011-37)
Mozilla: Integer underflow when using JavaScript RegExp (MFSA 2011-37)
Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via JavaScript code containing a large RegExp expression.
Package: firefox (Red Hat Enterprise Linux Extended Update Support 5.7) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update Support 5.7) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 6.1) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update Support 6.1) - Affected
GHSA
GHSA-2rjf-9fvj-83c2: Integer underflow in Mozilla Firefox 3
ghsa_unreviewed·2022-05-17
CVE-2011-2998 [HIGH] GHSA-2rjf-9fvj-83c2: Integer underflow in Mozilla Firefox 3
Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via JavaScript code containing a large RegExp expression.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.htmlhttp://www.debian.org/security/2011/dsa-2312http://www.debian.org/security/2011/dsa-2313http://www.debian.org/security/2011/dsa-2317http://www.mandriva.com/security/advisories?name=MDVSA-2011:139http://www.mandriva.com/security/advisories?name=MDVSA-2011:140http://www.mandriva.com/security/advisories?name=MDVSA-2011:141http://www.mozilla.org/security/announce/2011/mfsa2011-37.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1341.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=684815https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14012http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.htmlhttp://www.debian.org/security/2011/dsa-2312http://www.debian.org/security/2011/dsa-2313http://www.debian.org/security/2011/dsa-2317http://www.mandriva.com/security/advisories?name=MDVSA-2011:139http://www.mandriva.com/security/advisories?name=MDVSA-2011:140http://www.mandriva.com/security/advisories?name=MDVSA-2011:141http://www.mozilla.org/security/announce/2011/mfsa2011-37.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1341.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=684815https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14012
2011-09-30
Published