CVE-2011-3003Improper Restriction of Operations within the Bounds of a Memory Buffer in Mozilla Firefox

Severity
10.0CRITICALNVD
EPSS
1.5%
top 18.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 29
Latest updateMay 14

Description

Mozilla Firefox before 7.0 and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unspecified WebGL test case that triggers a memory-allocation error and a resulting out-of-bounds write operation.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDmozilla/firefox< 7.0

🔴Vulnerability Details

2
GHSA
GHSA-p22g-36v4-7hhj: Mozilla Firefox before 72022-05-14
CVEList
CVE-2011-3003: Mozilla Firefox before 72011-09-29

📋Vendor Advisories

2
Ubuntu
Mozvoikko, ubufox, webfav update2011-10-04
Ubuntu
Firefox vulnerabilities2011-09-29
CVE-2011-3003 — Mozilla Firefox vulnerability | cvebase