CVE-2011-3664
published 2011-12-21CVE-2011-3664: Mozilla Firefox before 9.0, Thunderbird before 9.0, and SeaMonkey before 2.6 on Mac OS X do not properly handle certain DOM frame deletions by plugins, which…
PriorityP422medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.36%
68.5th percentile
Mozilla Firefox before 9.0, Thunderbird before 9.0, and SeaMonkey before 2.6 on Mac OS X do not properly handle certain DOM frame deletions by plugins, which allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) or possibly have unspecified other impact via a crafted web site.
Affected
290 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 8.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qmxw-9h6q-w66q: Mozilla Firefox before 9
ghsa_unreviewed·2022-05-17
CVE-2011-3664 [MEDIUM] GHSA-qmxw-9h6q-w66q: Mozilla Firefox before 9
Mozilla Firefox before 9.0, Thunderbird before 9.0, and SeaMonkey before 2.6 on Mac OS X do not properly handle certain DOM frame deletions by plugins, which allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) or possibly have unspecified other impact via a crafted web site.
Red Hat
Mozilla: Multiple security flaws fixed in v3.6.25 (Mac) and v9
vendor_redhat·2011-12-20·CVSS 6.8
CVE-2011-3664 [MEDIUM] Mozilla: Multiple security flaws fixed in v3.6.25 (Mac) and v9
Mozilla: Multiple security flaws fixed in v3.6.25 (Mac) and v9
Mozilla Firefox before 9.0, Thunderbird before 9.0, and SeaMonkey before 2.6 on Mac OS X do not properly handle certain DOM frame deletions by plugins, which allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) or possibly have unspecified other impact via a crafted web site.
Statement: This issue did not affect the version of firefox and thunderbird packages as shipped with Red Hat Enterprise Linux 4, 5 and 6. This issue did not affect the version of seamonkey package as shipped with Red Hat Enterprise Linux 4.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/47302http://secunia.com/advisories/47334http://www.mozilla.org/security/announce/2011/mfsa2011-57.htmlhttp://www.securitytracker.com/id?1026445http://www.securitytracker.com/id?1026446http://www.securitytracker.com/id?1026447https://bugzilla.mozilla.org/show_bug.cgi?id=649079https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14574http://secunia.com/advisories/47302http://secunia.com/advisories/47334http://www.mozilla.org/security/announce/2011/mfsa2011-57.htmlhttp://www.securitytracker.com/id?1026445http://www.securitytracker.com/id?1026446http://www.securitytracker.com/id?1026447https://bugzilla.mozilla.org/show_bug.cgi?id=649079https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14574
2011-12-21
Published