10
CVSSv2

CVE-2011-2988

Published: 18/08/2011 Updated: 19/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in an unspecified string class in the WebGL shader implementation in Mozilla Firefox 4.x through 5, Thunderbird prior to 6, SeaMonkey 2.x prior to 2.3, and possibly other products allows remote malicious users to execute arbitrary code or cause a denial of service (application crash) via a long source-code block for a shader.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla seamonkey 2.0

mozilla seamonkey 2.0.1

mozilla seamonkey 2.0.10

mozilla seamonkey 2.0.4

mozilla seamonkey 2.0.5

mozilla seamonkey 2.1

mozilla seamonkey 2.2

mozilla firefox 4.0

mozilla firefox 4.0.1

mozilla firefox 5.0

mozilla seamonkey 2.0.11

mozilla seamonkey 2.0.12

mozilla seamonkey 2.0.6

mozilla seamonkey 2.0.7

mozilla thunderbird

mozilla seamonkey 2.0.2

mozilla seamonkey 2.0.3

mozilla seamonkey 2.0.13

mozilla seamonkey 2.0.14

mozilla seamonkey 2.0.8

mozilla seamonkey 2.0.9

Vendor Advisories

This update provides a compatible Mozvoikko for Firefox 6 ...
A regression caused Firefox to crash while spell checking in Finnish ...
Multiple Firefox vulnerabilities have been fixed ...
Mozilla Foundation Security Advisory 2011-33 Security issues addressed in SeaMonkey 23 Announced August 16, 2011 Impact Critical Products SeaMonkey Fixed in SeaMonkey 23 ...
Mozilla Foundation Security Advisory 2011-31 Security issues addressed in Thunderbird 6 Announced August 16, 2011 Impact Critical Products Thunderbird Fixed in Thunderbird 6 ...
Mozilla Foundation Security Advisory 2011-29 Security issues addressed in Firefox 6 Announced August 16, 2011 Impact Critical Products Firefox Fixed in Firefox 6 ...