CVE-2011-2999Cross-site Scripting in Mozilla Firefox

Severity
4.3MEDIUMNVD
EPSS
0.7%
top 27.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 29
Latest updateMay 17

Description

Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6.0, and SeaMonkey before 2.3 do not properly handle "location" as the name of a frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, a different vulnerability than CVE-2010-0170.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/firefox3.6.22+23
NVDmozilla/seamonkey2.1+52

🔴Vulnerability Details

2
GHSA
GHSA-f562-g9gh-gpgg: Mozilla Firefox before 32022-05-17
CVEList
CVE-2011-2999: Mozilla Firefox before 32011-09-29

📋Vendor Advisories

5
Ubuntu
Mozvoikko, ubufox, webfav update2011-10-04
Ubuntu
Firefox vulnerabilities2011-09-29
Ubuntu
Firefox and Xulrunner vulnerabilities2011-09-28
Ubuntu
Thunderbird vulnerabilities2011-09-28
Red Hat
Mozilla: XSS via plugins and shadowed window.location object (MFSA 2011-38)2011-09-28

💬Community

1
Bugzilla
CVE-2011-2999 Mozilla: XSS via plugins and shadowed window.location object (MFSA 2011-38)2011-09-28
CVE-2011-2999 — Cross-site Scripting in Mozilla Firefox | cvebase