4.3
CVSSv2

CVE-2011-3000

Published: 29/09/2011 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Mozilla Firefox prior to 3.6.23 and 4.x through 6, Thunderbird prior to 7.0, and SeaMonkey prior to 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote malicious users to conduct HTTP response splitting attacks via crafted header values.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.6.2

mozilla firefox 3.6.3

mozilla firefox 3.6.11

mozilla firefox 3.6.12

mozilla firefox 3.6.19

mozilla firefox 3.6.20

mozilla firefox 3.6

mozilla firefox 3.6.9

mozilla firefox 3.6.10

mozilla firefox 3.6.17

mozilla firefox 3.6.18

mozilla firefox 3.6.4

mozilla firefox 3.6.6

mozilla firefox 3.6.13

mozilla firefox 3.6.14

mozilla firefox 3.6.21

mozilla firefox

mozilla firefox 3.6.7

mozilla firefox 3.6.8

mozilla firefox 3.6.15

mozilla firefox 3.6.16

mozilla firefox 4.0

mozilla firefox 5.0

mozilla firefox 6.0

mozilla firefox 4.0.1

mozilla thunderbird 0.4

mozilla thunderbird 0.5

mozilla thunderbird 1.0

mozilla thunderbird 1.0.1

mozilla thunderbird 1.0.7

mozilla thunderbird 1.0.8

mozilla thunderbird 1.5.0.14

mozilla thunderbird 1.5.0.2

mozilla thunderbird 1.5.0.3

mozilla thunderbird 1.5.1

mozilla thunderbird 1.5.2

mozilla thunderbird 2.0.0.11

mozilla thunderbird 2.0.0.12

mozilla thunderbird 0.2

mozilla thunderbird 0.3

mozilla thunderbird 0.8

mozilla thunderbird 0.9

mozilla thunderbird 1.0.5

mozilla thunderbird 1.0.6

mozilla thunderbird 1.5.0.12

mozilla thunderbird 1.5.0.13

mozilla thunderbird 1.5.0.8

mozilla thunderbird 1.5.0.9

mozilla thunderbird 2.0.0.0

mozilla thunderbird 2.0.0.1

mozilla thunderbird 2.0.0.17

mozilla thunderbird 2.0.0.18

mozilla thunderbird 2.0.0.19

mozilla thunderbird 2.0.0.4

mozilla thunderbird 2.0.0.5

mozilla thunderbird 2.0_.14

mozilla thunderbird 2.0_.4

mozilla thunderbird 3.0.10

mozilla thunderbird 3.0.11

mozilla thunderbird 3.0.2

mozilla thunderbird 3.0.9

mozilla thunderbird 3.1

mozilla thunderbird 3.1.5

mozilla thunderbird 3.1.6

mozilla thunderbird 0.6

mozilla thunderbird 0.7

mozilla thunderbird 0.7.1

mozilla thunderbird 1.0.2

mozilla thunderbird 1.0.3

mozilla thunderbird 1.5

mozilla thunderbird 1.5.0.1

mozilla thunderbird 1.5.0.4

mozilla thunderbird 1.5.0.5

mozilla thunderbird 1.7.1

mozilla thunderbird 2.0.0.13

mozilla thunderbird 2.0.0.14

mozilla thunderbird 2.0.0.21

mozilla thunderbird 2.0.0.22

mozilla thunderbird 2.0.0.8

mozilla thunderbird 2.0.0.9

mozilla thunderbird 2.0_.9

mozilla thunderbird 2.0_8

mozilla thunderbird 3.0.5

mozilla thunderbird 3.0.6

mozilla thunderbird 3.1.11

mozilla thunderbird 3.1.2

mozilla thunderbird 3.1.9

mozilla thunderbird 5.0

mozilla thunderbird 0.1

mozilla thunderbird 0.7.2

mozilla thunderbird 0.7.3

mozilla thunderbird 1.0.4

mozilla thunderbird 1.5.0.10

mozilla thunderbird 1.5.0.11

mozilla thunderbird 1.5.0.6

mozilla thunderbird 1.5.0.7

mozilla thunderbird 1.7.3

mozilla thunderbird 2.0

mozilla thunderbird 2.0.0.15

mozilla thunderbird 2.0.0.16

mozilla thunderbird 2.0.0.23

mozilla thunderbird 2.0.0.3

mozilla thunderbird 2.0_.12

mozilla thunderbird 2.0_.13

mozilla thunderbird 2.0.0.2

mozilla thunderbird 2.0.0.20

mozilla thunderbird 2.0.0.6

mozilla thunderbird 2.0.0.7

mozilla thunderbird 2.0_.5

mozilla thunderbird 2.0_.6

mozilla thunderbird 3.0.3

mozilla thunderbird 3.0.4

mozilla thunderbird 3.1.1

mozilla thunderbird 3.1.10

mozilla thunderbird 3.1.7

mozilla thunderbird 3.1.8

mozilla thunderbird 3.0

mozilla thunderbird 3.0.1

mozilla thunderbird 3.0.7

mozilla thunderbird 3.0.8

mozilla thunderbird 3.1.3

mozilla thunderbird 3.1.4

mozilla thunderbird

mozilla seamonkey 1.0.1

mozilla seamonkey 1.0.2

mozilla seamonkey 1.0.9

mozilla seamonkey 1.0.99

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.10

mozilla seamonkey 1.1.18

mozilla seamonkey 1.1.19

mozilla seamonkey 1.0.5

mozilla seamonkey 1.0.6

mozilla seamonkey 1.0

mozilla seamonkey 1.1.13

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.15

mozilla seamonkey 1.1.4

mozilla seamonkey 1.1.5

mozilla seamonkey 1.1

mozilla seamonkey 1.5.0.10

mozilla seamonkey 2.0.13

mozilla seamonkey 2.0.14

mozilla seamonkey 2.0.8

mozilla seamonkey 2.0.9

mozilla seamonkey 2.0

mozilla seamonkey 2.0a1

mozilla seamonkey 1.0.3

mozilla seamonkey 1.0.4

mozilla seamonkey 1.1.11

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.2

mozilla seamonkey 1.1.3

mozilla seamonkey 1.1.9

mozilla seamonkey 2.0.10

mozilla seamonkey 2.0.11

mozilla seamonkey 2.0.12

mozilla seamonkey 2.0.6

mozilla seamonkey 2.0.7

mozilla seamonkey

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0.8

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.17

mozilla seamonkey 1.1.6

mozilla seamonkey 1.5.0.8

mozilla seamonkey 1.5.0.9

mozilla seamonkey 2.0.2

mozilla seamonkey 2.0.3

mozilla seamonkey 2.0a1pre

mozilla seamonkey 2.1

mozilla seamonkey 1.1.7

mozilla seamonkey 1.1.8

mozilla seamonkey 2.0.1

mozilla seamonkey 2.0.4

mozilla seamonkey 2.0.5

Vendor Advisories

Several vulnerabilities have been found in Iceweasel, a web browser based on Firefox: CVE-2011-2372 Mariusz Mlynski discovered that websites could open a download dialog — which has open as the default action —, while a user presses the ENTER key CVE-2011-2995 Benjamin Smedberg, Bob Clary and Jesse Ruderman discovered crashes ...
Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey: CVE-2011-2372 Mariusz Mlynski discovered that websites could open a download dialog — which has open as the default action —, while a user presses the ENTER key CVE-2011-2995 Benjamin Smedberg, Bob Clary and Jesse Ruderman di ...
Multiple vulnerabilities were fixed in Thunderbird ...
This update provides packages compatible with Firefox 7 ...
Firefox could be made to crash or possibly run programs as your login if it opened a malicious website ...
Multiple vulnerabilities have been fixed in Firefox and Xulrunner ...
Mozilla Foundation Security Advisory 2011-39 Defense against multiple Location headers due to CRLF Injection Announced September 27, 2011 Reporter Ian Graham Impact Moderate Products Firefox, SeaMonkey, Thunderbird Fixe ...