4.3
CVSSv2

CVE-2011-2605

Published: 30/06/2011 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox prior to 3.6.18 and 4.x up to and including 4.0.1, and Thunderbird prior to 3.1.11, allows remote malicious users to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.5.1

mozilla firefox 3.5.2

mozilla firefox 3.5.8

mozilla firefox 3.5

mozilla firefox 3.0.11

mozilla firefox 3.0.10

mozilla firefox 3.0.3

mozilla firefox 3.0.2

mozilla firefox 2.0.0.9

mozilla firefox 2.0.0.17

mozilla firefox 2.0

mozilla firefox 2.0.0.18

mozilla firefox 1.5

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.10

mozilla firefox 1.5.3

mozilla firefox 1.5.0.7

mozilla firefox 1.0.3

mozilla firefox 1.0.2

mozilla firefox 3.5.12

mozilla firefox 3.5.13

mozilla firefox 3.6.12

mozilla firefox 3.6.2

mozilla firefox 3.6.9

mozilla firefox 3.6.13

mozilla firefox 3.5.18

mozilla firefox 3.5.3

mozilla firefox 3.5.4

mozilla firefox 3.0.17

mozilla firefox 3.0.16

mozilla firefox 3.0.9

mozilla firefox 3.0.8

mozilla firefox 3.0.1

mozilla firefox 3.0

mozilla firefox 2.0.0.10

mozilla firefox 2.0.0.16

mozilla firefox 2.0.0.6

mozilla firefox 2.0.0.5

mozilla firefox 1.5.0.5

mozilla firefox 1.5.0.2

mozilla firefox 1.5.4

mozilla firefox 1.5.1

mozilla firefox 1.5.8

mozilla firefox 1.5.7

mozilla firefox 1.0.5

mozilla firefox 1.0.4

mozilla firefox 1.0.7

mozilla firefox 3.5.14

mozilla firefox 3.5.15

mozilla firefox 3.6.8

mozilla firefox 3.6.6

mozilla firefox 3.5.19

mozilla firefox 3.6.14

mozilla firefox 3.5.7

mozilla firefox 3.5.10

mozilla firefox 3.5.9

mozilla firefox 3.0.13

mozilla firefox 3.0.12

mozilla firefox 3.0.5

mozilla firefox 3.0.4

mozilla firefox 2.0.0.20

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.13

mozilla firefox 2.0.0.7

mozilla firefox 2.0.0.2

mozilla firefox 2.0.0.1

mozilla firefox 1.5.0.1

mozilla firefox 1.5.0.9

mozilla firefox 1.5.0.6

mozilla firefox 1.0.1

mozilla firefox 1.0

mozilla firefox 3.5.11

mozilla firefox 3.6.4

mozilla firefox 3.6

mozilla firefox 3.6.11

mozilla firefox 3.6.10

mozilla firefox

mozilla firefox 3.5.5

mozilla firefox 3.5.6

mozilla firefox 3.0.15

mozilla firefox 3.0.14

mozilla firefox 3.0.7

mozilla firefox 3.0.6

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.12

mozilla firefox 2.0.0.19

mozilla firefox 2.0.0.11

mozilla firefox 2.0.0.15

mozilla firefox 2.0.0.4

mozilla firefox 2.0.0.3

mozilla firefox 1.5.0.3

mozilla firefox 1.5.0.11

mozilla firefox 1.5.0.12

mozilla firefox 1.5.2

mozilla firefox 1.5.0.8

mozilla firefox 1.5.6

mozilla firefox 1.5.5

mozilla firefox 1.0.6

mozilla firefox 1.0.8

mozilla firefox 3.5.16

mozilla firefox 3.5.17

mozilla firefox 3.6.7

mozilla firefox 3.6.3

mozilla firefox 3.6.15

mozilla firefox 3.6.16

mozilla thunderbird 2.0.0.1

mozilla thunderbird 2.0.0.0

mozilla thunderbird 1.5.2

mozilla thunderbird 1.5.1

mozilla thunderbird 1.0.6

mozilla thunderbird 1.0.7

mozilla thunderbird 1.0.4

mozilla thunderbird 3.0.7

mozilla thunderbird 1.5.0.4

mozilla thunderbird 3.1.6

mozilla thunderbird 1.5.0.2

mozilla thunderbird 3.1.2

mozilla thunderbird 3.0.10

mozilla thunderbird 2.0.0.16

mozilla thunderbird 2.0.0.23

mozilla thunderbird 1.7.1

mozilla thunderbird 3.0

mozilla thunderbird 2.0.0.3

mozilla thunderbird 2.0.0.19

mozilla thunderbird 2.0.0.12

mozilla thunderbird 1.0.8

mozilla thunderbird 1.5

mozilla thunderbird 1.0.5

mozilla thunderbird 3.1.4

mozilla thunderbird 1.5.0.6

mozilla thunderbird 1.5.0.7

mozilla thunderbird 3.0.6

mozilla thunderbird 3.1.1

mozilla thunderbird 2.0.0.14

mozilla thunderbird 2.0.0.17

mozilla thunderbird 1.7.3

mozilla thunderbird 1.5.0.13

mozilla thunderbird 1.0.1

mozilla thunderbird 0.3

mozilla thunderbird 0.4

mozilla thunderbird 2.0.0.6

mozilla thunderbird 1.0

mozilla thunderbird 0.5

mozilla thunderbird 0.6

mozilla thunderbird

mozilla thunderbird 1.5.0.9

mozilla thunderbird 1.5.0.8

mozilla thunderbird 2.0.0.4

mozilla thunderbird 3.0.3

mozilla thunderbird 3.0.1

mozilla thunderbird 1.0.3

mozilla thunderbird 3.0.8

mozilla thunderbird 3.1.3

mozilla thunderbird 3.0.11

mozilla thunderbird 1.5.0.10

mozilla thunderbird 1.5.0.11

mozilla thunderbird 2.0

mozilla thunderbird 2.0.0.21

mozilla thunderbird 2.0.0.22

mozilla thunderbird 2.0.0.9

mozilla thunderbird 0.7

mozilla thunderbird 0.7.1

mozilla thunderbird 0.1

mozilla thunderbird 0.2

mozilla thunderbird 3.1.8

mozilla thunderbird 3.1.9

mozilla thunderbird 3.0.5

mozilla thunderbird 2.0.0.2

mozilla thunderbird 2.0.0.5

mozilla thunderbird 3.0.2

mozilla thunderbird 2.0.0.8

mozilla thunderbird 1.0.2

mozilla thunderbird 1.5.0.3

mozilla thunderbird 3.1.7

mozilla thunderbird 3.1.5

mozilla thunderbird 1.5.0.1

mozilla thunderbird 3.0.9

mozilla thunderbird 3.1

mozilla thunderbird 2.0.0.7

mozilla thunderbird 1.5.0.12

mozilla thunderbird 1.5.0.5

mozilla thunderbird 1.5.0.14

mozilla thunderbird 0.7.2

mozilla thunderbird 0.7.3

mozilla thunderbird 0.8

mozilla thunderbird 0.9

mozilla thunderbird 3.0.4

mozilla thunderbird 2.0.0.18

mozilla firefox 4.0

mozilla firefox 4.0.1