CVE-2011-3004
published 2011-09-29CVE-2011-3004: The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.14%
62.9th percentile
The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior.
Affected
266 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.6.23 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2011-12-22·CVSS 4.3
CVE-2011-3647 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Multiple vulnerabilities have been fixed in Thunderbird.
It was discovered that CVE-2011-3004, which addressed possible privilege
escalation in addons, also affected Thunderbird 3.1. An attacker could
potentially exploit a user who had installed an add-on that used
loadSubscript in vulnerable ways. (CVE-2011-3647)
Yosuke Hasegawa discovered that the Mozilla browser engine mishandled
invalid sequences in the Shift-JIS encoding. It may be possible to trigger
this crash without the use of debugging APIs, which might allow malicious
websites to exploit this vulnerability. An attacker could possibly use this
flaw this to steal data or inject malicious scripts into web content.
(CVE-2011-3648)
Marc Schoenefeld discovered that using Firebug to profi
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2011-11-10·CVSS 4.3
CVE-2011-3647 [MEDIUM] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Multiple vulnerabilities have been fixed in Firefox and Xulrunner.
It was discovered that CVE-2011-3004, which addressed possible privilege
escalation in addons, also affected Firefox 3.6. An attacker could
potentially exploit Firefox when an add-on was installed that used
loadSubscript in vulnerable ways. (CVE-2011-3647)
Yosuke Hasegawa discovered that the Mozilla browser engine mishandled
invalid sequences in the Shift-JIS encoding. A malicious website could
possibly use this flaw this to steal data or inject malicious scripts into
web content. (CVE-2011-3648)
Marc Schoenefeld discovered that using Firebug to profile a JavaScript file
with many functions would cause Firefox to crash. An attacker might be able
to exploit this witho
Red Hat
Mozilla: loadSubScript is unwrapping XPCNativeWrapper scope parameter (MFSA 2011-43)
vendor_redhat·2011-11-09·CVSS 4.3
CVE-2011-3004 [MEDIUM] Mozilla: loadSubScript is unwrapping XPCNativeWrapper scope parameter (MFSA 2011-43)
Mozilla: loadSubScript is unwrapping XPCNativeWrapper scope parameter (MFSA 2011-43)
The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior.
Statement: Not vulnerable. This issue did not affect the versions of firefox as shipped with Red Hat Enterprise Linux 5 or 6.
Red Hat
Mozilla: Security problem with loadSubScript on 1.9.2 branch (MFSA 2011-46)
vendor_redhat·2011-11-08·CVSS 4.3
CVE-2011-3647 [MEDIUM] Mozilla: Security problem with loadSubScript on 1.9.2 branch (MFSA 2011-46)
Mozilla: Security problem with loadSubScript on 1.9.2 branch (MFSA 2011-46)
The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior, a related issue to CVE-2011-3004.
Package: firefox (Red Hat Enterprise Linux Extended Update Support 6.1) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update Support 6.1) - Affected
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2011-09-29·CVSS 3.5
CVE-2011-3005 [LOW] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or possibly run programs as your login if it
opened a malicious website.
Benjamin Smedberg, Bob Clary, Jesse Ruderman, Bob Clary, Andrew McCreight,
Andreas Gal, Gary Kwong, Igor Bukanov, Jason Orendorff, Jesse Ruderman, and
Marcia Knous discovered multiple memory vulnerabilities in the browser
rendering engine. An attacker could use these to possibly execute arbitrary
code with the privileges of the user invoking Firefox. (CVE-2011-2995,
CVE-2011-2997)
Boris Zbarsky discovered that a frame named "location" could shadow the
window.location object unless a script in a page grabbed a reference to the
true object before the frame was created. This is in violation of the Same
Origin Policy. A malicious website could possi
GHSA
GHSA-jqqv-7cc8-34qh: The JSSubScriptLoader in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2011-3647 [MEDIUM] CWE-20 GHSA-jqqv-7cc8-34qh: The JSSubScriptLoader in Mozilla Firefox before 3
The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior, a related issue to CVE-2011-3004.
GHSA
GHSA-fwxw-xrff-9f5q: The JSSubScriptLoader in Mozilla Firefox 4
ghsa_unreviewed·2022-05-17
CVE-2011-3004 [MEDIUM] CWE-20 GHSA-fwxw-xrff-9f5q: The JSSubScriptLoader in Mozilla Firefox 4
The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior.
No detection rules found.
No public exploits indexed.
http://www.mandriva.com/security/advisories?name=MDVSA-2011:141http://www.mozilla.org/security/announce/2011/mfsa2011-43.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=653926https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14121http://www.mandriva.com/security/advisories?name=MDVSA-2011:141http://www.mozilla.org/security/announce/2011/mfsa2011-43.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=653926https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14121
2011-09-29
Published