4.3
CVSSv2

CVE-2011-2999

Published: 29/09/2011 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Mozilla Firefox prior to 3.6.23 and 4.x through 5, Thunderbird prior to 6.0, and SeaMonkey prior to 2.3 do not properly handle "location" as the name of a frame, which allows remote malicious users to bypass the Same Origin Policy via a crafted web site, a different vulnerability than CVE-2010-0170.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.6

mozilla firefox 3.6.9

mozilla firefox 3.6.10

mozilla firefox 3.6.17

mozilla firefox 3.6.18

mozilla firefox 3.6.4

mozilla firefox 3.6.6

mozilla firefox 3.6.13

mozilla firefox 3.6.14

mozilla firefox 3.6.21

mozilla firefox

mozilla firefox 3.6.2

mozilla firefox 3.6.3

mozilla firefox 3.6.11

mozilla firefox 3.6.12

mozilla firefox 3.6.19

mozilla firefox 3.6.20

mozilla firefox 3.6.7

mozilla firefox 3.6.8

mozilla firefox 3.6.15

mozilla firefox 3.6.16

mozilla firefox 4.0

mozilla firefox 5.0

mozilla firefox 4.0.1

mozilla thunderbird 0.3

mozilla thunderbird 0.4

mozilla thunderbird 0.9

mozilla thunderbird 1.0

mozilla thunderbird 1.0.6

mozilla thunderbird 1.0.7

mozilla thunderbird 1.5.0.13

mozilla thunderbird 1.5.0.14

mozilla thunderbird 1.5.0.2

mozilla thunderbird 1.5.0.9

mozilla thunderbird 1.5.1

mozilla thunderbird 2.0.0.1

mozilla thunderbird 2.0.0.11

mozilla thunderbird 2.0.0.18

mozilla thunderbird 2.0.0.19

mozilla thunderbird 2.0.0.2

mozilla thunderbird 2.0.0.5

mozilla thunderbird 2.0.0.6

mozilla thunderbird 2.0_.4

mozilla thunderbird 2.0_.5

mozilla thunderbird 3.0.2

mozilla thunderbird 3.0.3

mozilla thunderbird 3.1

mozilla thunderbird 3.1.1

mozilla thunderbird 3.1.6

mozilla thunderbird 3.1.7

mozilla thunderbird 0.7.1

mozilla thunderbird 0.7.2

mozilla thunderbird 1.0.3

mozilla thunderbird 1.0.4

mozilla thunderbird 1.5.0.1

mozilla thunderbird 1.5.0.10

mozilla thunderbird 1.5.0.5

mozilla thunderbird 1.5.0.6

mozilla thunderbird 1.7.1

mozilla thunderbird 1.7.3

mozilla thunderbird 2.0.0.14

mozilla thunderbird 2.0.0.15

mozilla thunderbird 2.0.0.22

mozilla thunderbird 2.0.0.23

mozilla thunderbird 2.0.0.9

mozilla thunderbird 2.0_.12

mozilla thunderbird 2.0_8

mozilla thunderbird 3.0

mozilla thunderbird 3.0.6

mozilla thunderbird 3.0.7

mozilla thunderbird 3.1.2

mozilla thunderbird 3.1.3

mozilla thunderbird

mozilla thunderbird 0.5

mozilla thunderbird 0.6

mozilla thunderbird 0.7

mozilla thunderbird 1.0.1

mozilla thunderbird 1.0.2

mozilla thunderbird 1.0.8

mozilla thunderbird 1.5

mozilla thunderbird 1.5.0.3

mozilla thunderbird 1.5.0.4

mozilla thunderbird 1.5.2

mozilla thunderbird 2.0.0.12

mozilla thunderbird 2.0.0.13

mozilla thunderbird 2.0.0.20

mozilla thunderbird 2.0.0.21

mozilla thunderbird 2.0.0.7

mozilla thunderbird 2.0.0.8

mozilla thunderbird 2.0_.6

mozilla thunderbird 2.0_.9

mozilla thunderbird 3.0.4

mozilla thunderbird 3.0.5

mozilla thunderbird 3.1.10

mozilla thunderbird 3.1.11

mozilla thunderbird 3.1.8

mozilla thunderbird 3.1.9

mozilla thunderbird 0.1

mozilla thunderbird 0.2

mozilla thunderbird 0.7.3

mozilla thunderbird 0.8

mozilla thunderbird 1.0.5

mozilla thunderbird 1.5.0.11

mozilla thunderbird 1.5.0.12

mozilla thunderbird 1.5.0.7

mozilla thunderbird 1.5.0.8

mozilla thunderbird 2.0

mozilla thunderbird 2.0.0.0

mozilla thunderbird 2.0.0.16

mozilla thunderbird 2.0.0.17

mozilla thunderbird 2.0.0.3

mozilla thunderbird 2.0.0.4

mozilla thunderbird 2.0_.13

mozilla thunderbird 2.0_.14

mozilla thunderbird 3.0.1

mozilla thunderbird 3.0.10

mozilla thunderbird 3.0.11

mozilla thunderbird 3.0.8

mozilla thunderbird 3.0.9

mozilla thunderbird 3.1.4

mozilla thunderbird 3.1.5

mozilla seamonkey 1.0.3

mozilla seamonkey 1.0.4

mozilla seamonkey 1.0

mozilla seamonkey 1.1.11

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.2

mozilla seamonkey 1.1.3

mozilla seamonkey 1.1.9

mozilla seamonkey 1.1

mozilla seamonkey 2.0.10

mozilla seamonkey 2.0.11

mozilla seamonkey 2.0.12

mozilla seamonkey 2.0.6

mozilla seamonkey 2.0.7

mozilla seamonkey 2.0

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0.8

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.17

mozilla seamonkey 1.1.5

mozilla seamonkey 1.1.6

mozilla seamonkey 1.5.0.8

mozilla seamonkey 1.5.0.9

mozilla seamonkey 2.0.2

mozilla seamonkey 2.0.3

mozilla seamonkey 2.0a1pre

mozilla seamonkey 2.1

mozilla seamonkey 1.0.5

mozilla seamonkey 1.0.6

mozilla seamonkey 1.1.13

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.15

mozilla seamonkey 1.1.4

mozilla seamonkey 1.5.0.10

mozilla seamonkey 1.0.1

mozilla seamonkey 1.0.2

mozilla seamonkey 1.0.9

mozilla seamonkey 1.0.99

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.10

mozilla seamonkey 1.1.18

mozilla seamonkey 1.1.19

mozilla seamonkey 1.1.7

mozilla seamonkey 1.1.8

mozilla seamonkey 2.0.1

mozilla seamonkey 2.0.4

mozilla seamonkey 2.0.5

mozilla seamonkey

mozilla seamonkey 2.0.13

mozilla seamonkey 2.0.14

mozilla seamonkey 2.0.8

mozilla seamonkey 2.0.9

mozilla seamonkey 2.0a1

Vendor Advisories

Several vulnerabilities have been found in Iceweasel, a web browser based on Firefox: CVE-2011-2372 Mariusz Mlynski discovered that websites could open a download dialog — which has open as the default action —, while a user presses the ENTER key CVE-2011-2995 Benjamin Smedberg, Bob Clary and Jesse Ruderman discovered crashes ...
Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey: CVE-2011-2372 Mariusz Mlynski discovered that websites could open a download dialog — which has open as the default action —, while a user presses the ENTER key CVE-2011-2995 Benjamin Smedberg, Bob Clary and Jesse Ruderman di ...
Multiple vulnerabilities were fixed in Thunderbird ...
This update provides packages compatible with Firefox 7 ...
Firefox could be made to crash or possibly run programs as your login if it opened a malicious website ...
Multiple vulnerabilities have been fixed in Firefox and Xulrunner ...
Mozilla Foundation Security Advisory 2011-38 XSS via plugins and shadowed windowlocation object Announced September 27, 2011 Reporter Boris Zbarsky Impact High Products Firefox, SeaMonkey, Thunderbird Fixed in ...