CVE-2011-2998Integer Overflow or Wraparound in Mozilla Firefox

Severity
10.0CRITICALNVD
EPSS
3.7%
top 12.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 30
Latest updateMay 17

Description

Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via JavaScript code containing a large RegExp expression.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDmozilla/firefox21 versions+20

🔴Vulnerability Details

1
GHSA
GHSA-2rjf-9fvj-83c2: Integer underflow in Mozilla Firefox 32022-05-17

📋Vendor Advisories

1
Red Hat
Mozilla: Integer underflow when using JavaScript RegExp (MFSA 2011-37)2011-09-28

💬Community

1
Bugzilla
CVE-2011-2998 Mozilla: Integer underflow when using JavaScript RegExp (MFSA 2011-37)2011-09-28