CVE-2011-3650Improper Restriction of Operations within the Bounds of a Memory Buffer in Mozilla Firefox

Severity
9.3CRITICALNVD
EPSS
1.3%
top 20.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 9
Latest updateMay 17

Description

Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is accessed by debugging APIs, as demonstrated by Firebug.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDmozilla/firefox3.6.23+132
NVDmozilla/thunderbird3.1.5+88

🔴Vulnerability Details

1
GHSA
GHSA-3238-3xx2-28gw: Mozilla Firefox before 32022-05-17

📋Vendor Advisories

6
Ubuntu
Thunderbird vulnerabilities2011-12-22
Ubuntu
Thunderbird vulnerabilities2011-11-28
Ubuntu
Mozvoikko and ubufox update2011-11-23
Ubuntu
Firefox vulnerabilities2011-11-23
Ubuntu
Firefox and Xulrunner vulnerabilities2011-11-10

💬Community

1
Bugzilla
CVE-2011-3650 Mozilla: crash while profiling page with many functions (MFSA 2011-49)2011-11-08