4.3
CVSSv2

CVE-2011-3004

Published: 29/09/2011 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey prior to 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote malicious users to gain privileges via a crafted web site that leverages certain unwrapping behavior.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 4.0.1

mozilla firefox 4.0

mozilla firefox 6.0

mozilla firefox 5.0

mozilla seamonkey 1.0

mozilla seamonkey 1.0.1

mozilla seamonkey 1.0.9

mozilla seamonkey 1.0.99

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.10

mozilla seamonkey 1.1.17

mozilla seamonkey 1.1.18

mozilla seamonkey 1.1.7

mozilla seamonkey 1.1.8

mozilla seamonkey 2.0

mozilla seamonkey 2.0.1

mozilla seamonkey 2.0.3

mozilla seamonkey 2.0.4

mozilla seamonkey 2.0.5

mozilla seamonkey 2.1

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0.8

mozilla seamonkey 1.1

mozilla seamonkey 1.1.15

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.5

mozilla seamonkey 1.1.6

mozilla seamonkey 1.5.0.8

mozilla seamonkey 1.5.0.9

mozilla seamonkey 2.0.14

mozilla seamonkey 2.0.2

mozilla seamonkey 2.0a1pre

mozilla seamonkey 1.0.2

mozilla seamonkey 1.0.3

mozilla seamonkey 1.1.11

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.19

mozilla seamonkey 1.1.2

mozilla seamonkey 1.1.3

mozilla seamonkey 1.1.9

mozilla seamonkey 2.0.10

mozilla seamonkey 2.0.11

mozilla seamonkey 2.0.6

mozilla seamonkey 2.0.7

mozilla seamonkey

mozilla seamonkey 1.0.4

mozilla seamonkey 1.0.5

mozilla seamonkey 1.0.6

mozilla seamonkey 1.1.13

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.4

mozilla seamonkey 1.5.0.10

mozilla seamonkey 2.0.12

mozilla seamonkey 2.0.13

mozilla seamonkey 2.0.8

mozilla seamonkey 2.0.9

mozilla seamonkey 2.0a1

Vendor Advisories

Multiple vulnerabilities have been fixed in Firefox and Xulrunner ...
Multiple vulnerabilities have been fixed in Thunderbird ...
Firefox could be made to crash or possibly run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2011-43 loadSubScript unwraps XPCNativeWrapper scope parameter Announced September 27, 2011 Reporter David Rees Impact Critical Products Firefox, SeaMonkey Fixed in ...