CVE-2011-3000 — Code Injection in Mozilla Firefox
Severity
4.3MEDIUMNVD
EPSS
1.3%
top 20.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 29
Latest updateMay 17
Description
Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9
Affected Packages3 packages
🔴Vulnerability Details
2💥Exploits & PoCs
7📋Vendor Advisories
5💬Community
1Bugzilla▶
CVE-2011-3000 Mozilla: Defense against multiple Location headers due to CRLF Injection (MFSA 2011-39)↗2011-09-28