CVE-2011-3648Cross-site Scripting in Mozilla Firefox

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 43.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 9
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 allows remote attackers to inject arbitrary web script or HTML via crafted text with Shift JIS encoding.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDmozilla/firefox3.6.23+132
NVDmozilla/thunderbird3.1.5+88

🔴Vulnerability Details

1
GHSA
GHSA-gwgh-7847-2vj4: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 32022-05-17

📋Vendor Advisories

6
Ubuntu
Thunderbird vulnerabilities2011-12-22
Ubuntu
Thunderbird vulnerabilities2011-11-28
Ubuntu
Mozvoikko and ubufox update2011-11-23
Ubuntu
Firefox vulnerabilities2011-11-23
Ubuntu
Firefox and Xulrunner vulnerabilities2011-11-10

💬Community

1
Bugzilla
CVE-2011-3648 Mozilla: Universal XSS likely with MultiByte charset (MFSA 2011-47)2011-11-08