3.5
CVSSv2

CVE-2011-2372

Published: 29/09/2011 Updated: 19/09/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Mozilla Firefox prior to 3.6.23 and 4.x through 6, Thunderbird prior to 7.0, and SeaMonkey prior to 2.4 do not prevent the starting of a download in response to the holding of the Enter key, which allows user-assisted remote malicious users to bypass intended access restrictions via a crafted web site.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.6.6

mozilla firefox 3.6.7

mozilla firefox 3.6.8

mozilla firefox 3.6.15

mozilla firefox 3.6.16

mozilla firefox 3.6

mozilla firefox 3.6.2

mozilla firefox 3.6.11

mozilla firefox 3.6.3

mozilla firefox 3.6.4

mozilla firefox 3.6.13

mozilla firefox 3.6.14

mozilla firefox 3.6.21

mozilla firefox

mozilla firefox 3.6.9

mozilla firefox 3.6.10

mozilla firefox 3.6.17

mozilla firefox 3.6.18

mozilla firefox 3.6.12

mozilla firefox 3.6.19

mozilla firefox 3.6.20

mozilla firefox 4.0

mozilla firefox 5.0

mozilla firefox 6.0

mozilla firefox 4.0.1

mozilla thunderbird 0.1

mozilla thunderbird 0.7.1

mozilla thunderbird 0.7.2

mozilla thunderbird 1.0.4

mozilla thunderbird 1.0.5

mozilla thunderbird 1.5.0.10

mozilla thunderbird 1.5.0.11

mozilla thunderbird 1.5.0.5

mozilla thunderbird 1.5.0.6

mozilla thunderbird 1.7.3

mozilla thunderbird 2.0

mozilla thunderbird 2.0.0.15

mozilla thunderbird 2.0.0.16

mozilla thunderbird 2.0.0.22

mozilla thunderbird 2.0.0.23

mozilla thunderbird 2.0_.12

mozilla thunderbird 2.0_.13

mozilla thunderbird 3.0

mozilla thunderbird 3.0.1

mozilla thunderbird 3.0.6

mozilla thunderbird 3.0.7

mozilla thunderbird 3.0.8

mozilla thunderbird 3.1.3

mozilla thunderbird 3.1.4

mozilla thunderbird

mozilla thunderbird 0.6

mozilla thunderbird 0.7

mozilla thunderbird 1.0.2

mozilla thunderbird 1.0.3

mozilla thunderbird 1.5

mozilla thunderbird 1.5.0.1

mozilla thunderbird 1.5.0.3

mozilla thunderbird 1.5.0.4

mozilla thunderbird 1.7.1

mozilla thunderbird 2.0.0.13

mozilla thunderbird 2.0.0.14

mozilla thunderbird 2.0.0.20

mozilla thunderbird 2.0.0.21

mozilla thunderbird 2.0.0.8

mozilla thunderbird 2.0.0.9

mozilla thunderbird 2.0_.9

mozilla thunderbird 2.0_8

mozilla thunderbird 3.0.4

mozilla thunderbird 3.0.5

mozilla thunderbird 3.1.11

mozilla thunderbird 3.1.2

mozilla thunderbird 3.1.9

mozilla thunderbird 5.0

mozilla thunderbird 0.2

mozilla thunderbird 0.3

mozilla thunderbird 0.7.3

mozilla thunderbird 0.8

mozilla thunderbird 1.0.6

mozilla thunderbird 1.5.0.12

mozilla thunderbird 1.5.0.13

mozilla thunderbird 1.5.0.7

mozilla thunderbird 1.5.0.8

mozilla thunderbird 1.5.0.9

mozilla thunderbird 2.0.0.0

mozilla thunderbird 2.0.0.1

mozilla thunderbird 2.0.0.17

mozilla thunderbird 2.0.0.18

mozilla thunderbird 2.0.0.3

mozilla thunderbird 2.0.0.4

mozilla thunderbird 2.0.0.5

mozilla thunderbird 2.0_.14

mozilla thunderbird 2.0_.4

mozilla thunderbird 3.0.10

mozilla thunderbird 3.0.11

mozilla thunderbird 3.0.9

mozilla thunderbird 3.1

mozilla thunderbird 3.1.5

mozilla thunderbird 3.1.6

mozilla thunderbird 0.4

mozilla thunderbird 0.5

mozilla thunderbird 0.9

mozilla thunderbird 1.0

mozilla thunderbird 1.0.1

mozilla thunderbird 1.0.7

mozilla thunderbird 1.0.8

mozilla thunderbird 1.5.0.14

mozilla thunderbird 1.5.0.2

mozilla thunderbird 1.5.1

mozilla thunderbird 1.5.2

mozilla thunderbird 2.0.0.11

mozilla thunderbird 2.0.0.12

mozilla thunderbird 2.0.0.19

mozilla thunderbird 2.0.0.2

mozilla thunderbird 2.0.0.6

mozilla thunderbird 2.0.0.7

mozilla thunderbird 2.0_.5

mozilla thunderbird 2.0_.6

mozilla thunderbird 3.0.2

mozilla thunderbird 3.0.3

mozilla thunderbird 3.1.1

mozilla thunderbird 3.1.10

mozilla thunderbird 3.1.7

mozilla thunderbird 3.1.8

mozilla seamonkey 1.0.4

mozilla seamonkey 1.0.5

mozilla seamonkey 1.0.6

mozilla seamonkey 1.0

mozilla seamonkey 1.1.13

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.4

mozilla seamonkey 1.1.5

mozilla seamonkey 1.1

mozilla seamonkey 1.5.0.10

mozilla seamonkey 2.0.12

mozilla seamonkey 2.0.13

mozilla seamonkey 2.0.8

mozilla seamonkey 2.0.9

mozilla seamonkey 2.0

mozilla seamonkey 2.0a1

mozilla seamonkey 1.0.1

mozilla seamonkey 1.0.9

mozilla seamonkey 1.0.99

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.10

mozilla seamonkey 1.1.17

mozilla seamonkey 1.1.18

mozilla seamonkey 1.1.7

mozilla seamonkey 1.1.8

mozilla seamonkey 2.0.1

mozilla seamonkey 2.0.3

mozilla seamonkey 2.0.4

mozilla seamonkey 2.1

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0.8

mozilla seamonkey 1.1.15

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.6

mozilla seamonkey 1.5.0.8

mozilla seamonkey 1.5.0.9

mozilla seamonkey 2.0.14

mozilla seamonkey 2.0.2

mozilla seamonkey 2.0a1pre

mozilla seamonkey 1.0.2

mozilla seamonkey 1.0.3

mozilla seamonkey 1.1.11

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.19

mozilla seamonkey 1.1.2

mozilla seamonkey 1.1.3

mozilla seamonkey 1.1.9

mozilla seamonkey 2.0.10

mozilla seamonkey 2.0.11

mozilla seamonkey 2.0.5

mozilla seamonkey 2.0.6

mozilla seamonkey 2.0.7

mozilla seamonkey

Vendor Advisories

Several vulnerabilities have been found in Iceweasel, a web browser based on Firefox: CVE-2011-2372 Mariusz Mlynski discovered that websites could open a download dialog — which has open as the default action —, while a user presses the ENTER key CVE-2011-2995 Benjamin Smedberg, Bob Clary and Jesse Ruderman discovered crashes ...
Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey: CVE-2011-2372 Mariusz Mlynski discovered that websites could open a download dialog — which has open as the default action —, while a user presses the ENTER key CVE-2011-2995 Benjamin Smedberg, Bob Clary and Jesse Ruderman di ...
Multiple vulnerabilities were fixed in Thunderbird ...
This update provides packages compatible with Firefox 7 ...
Firefox could be made to crash or possibly run programs as your login if it opened a malicious website ...
Multiple vulnerabilities have been fixed in Firefox and Xulrunner ...
Mozilla Foundation Security Advisory 2011-40 Code installation through holding down Enter Announced September 27, 2011 Reporter Mariusz Mlynski Impact Critical Products Firefox, SeaMonkey, Thunderbird Fixed in ...