CVE-2011-3666
published 2011-12-21CVE-2011-3666: Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted remote…
PriorityP426medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.03%
60.4th percentile
Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted file. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-2372 on Mac OS X.
Affected
219 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.6.24 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-97c6-9gg8-w889: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-17·CVSS 3.5
CVE-2011-3666 [LOW] GHSA-97c6-9gg8-w889: Mozilla Firefox before 3
Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted file. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-2372 on Mac OS X.
Red Hat
kernel: netfilter: nf_tables: unregister flowtable hooks on netns exit
vendor_redhat·2024-08-22·CVSS 5.5
CVE-2022-48935 [MEDIUM] CWE-416 kernel: netfilter: nf_tables: unregister flowtable hooks on netns exit
kernel: netfilter: nf_tables: unregister flowtable hooks on netns exit
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: unregister flowtable hooks on netns exit
Unregister flowtable hooks before they are releases via
nf_tables_flowtable_destroy() otherwise hook core reports UAF.
BUG: KASAN: use-after-free in nf_hook_entries_grow+0x5a7/0x700 net/netfilter/core.c:142 net/netfilter/core.c:142
Read of size 4 at addr ffff8880736f7438 by task syz-executor579/3666
CPU: 0 PID: 3666 Comm: syz-executor579 Not tainted 5.16.0-rc5-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:88 [inline]
__dump_stack lib/dump_stack.c:88 [inline] lib/dump_stack.c:106
dump_stack_lv
Red Hat
Mozilla: Multiple security flaws fixed in v3.6.25 (Mac) and v9
vendor_redhat·2011-12-20·CVSS 3.5
CVE-2011-3666 [LOW] Mozilla: Multiple security flaws fixed in v3.6.25 (Mac) and v9
Mozilla: Multiple security flaws fixed in v3.6.25 (Mac) and v9
Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted file. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-2372 on Mac OS X.
Statement: This issue did not affect the version of firefox and thunderbird packages as shipped with Red Hat Enterprise Linux 4, 5 and 6. This issue did not affect the version of seamonkey package as shipped with Red Hat Enterprise Linux 4.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.mozilla.org/security/announce/2011/mfsa2011-59.htmlhttp://www.securitytracker.com/id?1026445http://www.securitytracker.com/id?1026447https://bugzilla.mozilla.org/show_bug.cgi?id=704622https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14831http://www.mozilla.org/security/announce/2011/mfsa2011-59.htmlhttp://www.securitytracker.com/id?1026445http://www.securitytracker.com/id?1026447https://bugzilla.mozilla.org/show_bug.cgi?id=704622https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14831
2011-12-21
Published