CVE-2011-3650
published 2011-11-09CVE-2011-3650: Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many…
PriorityP429critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.33%
81.6th percentile
Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is accessed by debugging APIs, as demonstrated by Firebug.
Affected
222 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.6.23 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2011-12-22·CVSS 4.3
CVE-2011-3647 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Multiple vulnerabilities have been fixed in Thunderbird.
It was discovered that CVE-2011-3004, which addressed possible privilege
escalation in addons, also affected Thunderbird 3.1. An attacker could
potentially exploit a user who had installed an add-on that used
loadSubscript in vulnerable ways. (CVE-2011-3647)
Yosuke Hasegawa discovered that the Mozilla browser engine mishandled
invalid sequences in the Shift-JIS encoding. It may be possible to trigger
this crash without the use of debugging APIs, which might allow malicious
websites to exploit this vulnerability. An attacker could possibly use this
flaw this to steal data or inject malicious scripts into web content.
(CVE-2011-3648)
Marc Schoenefeld discovered that using Firebug to profi
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2011-11-28·CVSS 4.3
CVE-2011-3648 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Multiple vulnerabilities have been fixed in Thunderbird.
Yosuke Hasegawa discovered that the Mozilla browser engine mishandled
invalid sequences in the Shift-JIS encoding. It may be possible to trigger
this crash without the use of debugging APIs, which might allow malicious
websites to exploit this vulnerability. An attacker could possibly use this
flaw this to steal data or inject malicious scripts into web content.
(CVE-2011-3648)
Marc Schoenefeld discovered that using Firebug to profile a JavaScript file
with many functions would cause Firefox to crash. An attacker might be able
to exploit this without using the debugging APIs, which could potentially
remotely crash Thunderbird, resulting in a denial of service.
(CVE-2011-3650)
Jason Oren
Ubuntu
Mozvoikko and ubufox update
vendor_ubuntu·2011-11-23·CVSS 4.3
[MEDIUM] Mozvoikko and ubufox update
Title: Mozvoikko and ubufox update
Summary: This update provides packages compatible with Firefox 8.
USN-1277-1 fixed vulnerabilities in Firefox. This update provides updated
Mozvoikko and ubufox packages for use with Firefox 8.
Original advisory details:
Yosuke Hasegawa discovered that the Mozilla browser engine mishandled
invalid sequences in the Shift-JIS encoding. It may be possible to trigger
this crash without the use of debugging APIs, which might allow malicious
websites to exploit this vulnerability. An attacker could possibly use this
flaw this to steal data or inject malicious scripts into web content.
(CVE-2011-3648)
Marc Schoenefeld discovered that using Firebug to profile a JavaScript file
with many functions would cause Firefox to crash. An attacker might be able
to exp
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2011-11-23·CVSS 4.3
CVE-2011-3648 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Multiple vulnerabilities have been fixed in Firefox.
Yosuke Hasegawa discovered that the Mozilla browser engine mishandled
invalid sequences in the Shift-JIS encoding. It may be possible to trigger
this crash without the use of debugging APIs, which might allow malicious
websites to exploit this vulnerability. An attacker could possibly use this
flaw this to steal data or inject malicious scripts into web content.
(CVE-2011-3648)
Marc Schoenefeld discovered that using Firebug to profile a JavaScript file
with many functions would cause Firefox to crash. An attacker might be able
to exploit this without using the debugging APIs, which could potentially
remotely crash the browser, resulting in a denial of service.
(CVE-2011-3650)
Jason Orendorff, B
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2011-11-10·CVSS 4.3
CVE-2011-3647 [MEDIUM] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Multiple vulnerabilities have been fixed in Firefox and Xulrunner.
It was discovered that CVE-2011-3004, which addressed possible privilege
escalation in addons, also affected Firefox 3.6. An attacker could
potentially exploit Firefox when an add-on was installed that used
loadSubscript in vulnerable ways. (CVE-2011-3647)
Yosuke Hasegawa discovered that the Mozilla browser engine mishandled
invalid sequences in the Shift-JIS encoding. A malicious website could
possibly use this flaw this to steal data or inject malicious scripts into
web content. (CVE-2011-3648)
Marc Schoenefeld discovered that using Firebug to profile a JavaScript file
with many functions would cause Firefox to crash. An attacker might be able
to exploit this witho
Red Hat
Mozilla: crash while profiling page with many functions (MFSA 2011-49)
vendor_redhat·2011-11-08·CVSS 9.3
CVE-2011-3650 [CRITICAL] Mozilla: crash while profiling page with many functions (MFSA 2011-49)
Mozilla: crash while profiling page with many functions (MFSA 2011-49)
Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is accessed by debugging APIs, as demonstrated by Firebug.
Package: firefox (Red Hat Enterprise Linux Extended Update Support 6.1) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update Support 6.1) - Affected
GHSA
GHSA-3238-3xx2-28gw: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-17
CVE-2011-3650 [HIGH] CWE-119 GHSA-3238-3xx2-28gw: Mozilla Firefox before 3
Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is accessed by debugging APIs, as demonstrated by Firebug.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.htmlhttp://www.mozilla.org/security/announce/2011/mfsa2011-49.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1439.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=674776https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13870http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.htmlhttp://www.mozilla.org/security/announce/2011/mfsa2011-49.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1439.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=674776https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13870
2011-11-09
Published