9.3
CVSSv2

CVE-2011-3647

Published: 09/11/2011 Updated: 19/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The JSSubScriptLoader in Mozilla Firefox prior to 3.6.24 and Thunderbird prior to 3.1.6 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote malicious users to gain privileges via a crafted web site that leverages certain unwrapping behavior, a related issue to CVE-2011-3004.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.6.4

mozilla firefox 3.6.6

mozilla firefox 3.6.13

mozilla firefox 3.6.14

mozilla firefox 3.6.15

mozilla firefox 3.6.22

mozilla firefox

mozilla firefox 3.5.11

mozilla firefox 3.5.3

mozilla firefox 3.5

mozilla firefox 3.0.14

mozilla firefox 3.0.11

mozilla firefox 3.0.12

mozilla firefox 3.0.15

mozilla firefox 3.0.16

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.9

mozilla firefox 2.0.0.5

mozilla firefox 2.0.0.4

mozilla firefox 1.0.1

mozilla firefox 1.0

mozilla firefox 1.5

mozilla firefox 1.0.8

mozilla firefox 1.5.0.1

mozilla firefox 1.5.0.9

mozilla firefox 1.5.0.6

mozilla firefox 0.10

mozilla firefox 0.8

mozilla firefox 0.7

mozilla firefox 0.7.1

mozilla firefox 3.6.2

mozilla firefox 3.6.3

mozilla firefox 3.6.7

mozilla firefox 3.6.8

mozilla firefox 3.6.16

mozilla firefox 3.6.17

mozilla firefox 3.5.10

mozilla firefox 3.5.15

mozilla firefox 3.5.8

mozilla firefox 3.5.2

mozilla firefox 3.0.1

mozilla firefox 3.0.10

mozilla firefox 3.0.8

mozilla firefox 3.0.9

mozilla firefox 3.0.2

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.7

mozilla firefox 2.0

mozilla firefox 2.0.0.3

mozilla firefox 2.0.0.2

mozilla firefox 1.0.3

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.5

mozilla firefox 1.5.0.10

mozilla firefox 1.5.3

mozilla firefox 1.5.0.7

mozilla firefox 1.8

mozilla firefox 0.10.1

mozilla firefox 0.9.1

mozilla firefox 0.9

mozilla firefox 0.3

mozilla firefox 0.2

mozilla firefox 3.6.11

mozilla firefox 3.6.12

mozilla firefox 3.6.20

mozilla firefox 3.6.21

mozilla firefox 3.5.13

mozilla firefox 3.5.9

mozilla firefox 3.5.5

mozilla firefox 3.5.6

mozilla firefox 3.5.7

mozilla firefox 3.0.5

mozilla firefox 3.0

mozilla firefox 3.0.13

mozilla firefox 3.0.7

mozilla firefox 2.0.0.19

mozilla firefox 2.0.0.13

mozilla firefox 2.0.0.20

mozilla firefox 2.0.0.17

mozilla firefox 2.0.0.10

mozilla firefox 2.0.0.11

mozilla firefox 1.4.1

mozilla firefox 1.0.7

mozilla firefox 1.0.6

mozilla firefox 1.5.0.11

mozilla firefox 1.5.0.12

mozilla firefox 1.5.2

mozilla firefox 1.5.0.8

mozilla firefox 1.5.6

mozilla firefox 1.5.5

mozilla firefox 0.6.1

mozilla firefox 0.9.2

mozilla firefox 0.6

mozilla firefox 0.1

mozilla firefox 3.6

mozilla firefox 3.6.9

mozilla firefox 3.6.10

mozilla firefox 3.6.18

mozilla firefox 3.6.19

mozilla firefox 3.5.14

mozilla firefox 3.5.12

mozilla firefox 3.5.4

mozilla firefox 3.5.1

mozilla firefox 3.0.6

mozilla firefox 3.0.3

mozilla firefox 3.0.17

mozilla firefox 3.0.4

mozilla firefox 2.0.0.12

mozilla firefox 2.0.0.15

mozilla firefox 2.0.0.18

mozilla firefox 2.0.0.6

mozilla firefox 2.0.0.1

mozilla firefox 2.0.0.16

mozilla firefox 1.0.2

mozilla firefox 1.0.5

mozilla firefox 1.0.4

mozilla firefox 1.5.0.2

mozilla firefox 1.5.0.3

mozilla firefox 1.5.4

mozilla firefox 1.5.1

mozilla firefox 1.5.8

mozilla firefox 1.5.7

mozilla firefox 0.9.3

mozilla firefox 0.4

mozilla firefox 0.5

mozilla thunderbird 0.2

mozilla thunderbird 0.3

mozilla thunderbird 0.7.3

mozilla thunderbird 0.8

mozilla thunderbird 1.0.5

mozilla thunderbird 1.5.0.12

mozilla thunderbird 1.5.0.13

mozilla thunderbird 1.5.0.7

mozilla thunderbird 1.5.0.8

mozilla thunderbird 2.0

mozilla thunderbird 2.0.0.0

mozilla thunderbird 2.0.0.17

mozilla thunderbird 2.0.0.18

mozilla thunderbird 2.0.0.3

mozilla thunderbird 2.0.0.4

mozilla thunderbird 3.0.1

mozilla thunderbird 3.0.10

mozilla thunderbird 3.0.8

mozilla thunderbird 3.0.9

mozilla thunderbird 3.1.4

mozilla thunderbird

mozilla thunderbird 0.1

mozilla thunderbird 0.7.1

mozilla thunderbird 0.7.2

mozilla thunderbird 1.0.3

mozilla thunderbird 1.0.4

mozilla thunderbird 1.5.0.10

mozilla thunderbird 1.5.0.11

mozilla thunderbird 1.5.0.5

mozilla thunderbird 1.5.0.6

mozilla thunderbird 1.7.1

mozilla thunderbird 1.7.3

mozilla thunderbird 2.0.0.15

mozilla thunderbird 2.0.0.16

mozilla thunderbird 2.0.0.22

mozilla thunderbird 2.0.0.23

mozilla thunderbird 2.0.0.9

mozilla thunderbird 3.0

mozilla thunderbird 3.0.6

mozilla thunderbird 3.0.7

mozilla thunderbird 3.1.2

mozilla thunderbird 3.1.3

mozilla thunderbird 0.6

mozilla thunderbird 0.7

mozilla thunderbird 1.0.1

mozilla thunderbird 1.0.2

mozilla thunderbird 1.0.8

mozilla thunderbird 1.5

mozilla thunderbird 1.5.0.1

mozilla thunderbird 1.5.0.3

mozilla thunderbird 1.5.0.4

mozilla thunderbird 1.5.2

mozilla thunderbird 2.0.0.12

mozilla thunderbird 2.0.0.13

mozilla thunderbird 2.0.0.14

mozilla thunderbird 2.0.0.20

mozilla thunderbird 2.0.0.21

mozilla thunderbird 2.0.0.7

mozilla thunderbird 2.0.0.8

mozilla thunderbird 3.0.4

mozilla thunderbird 3.0.5

mozilla thunderbird 3.1.10

mozilla thunderbird 3.1.11

mozilla thunderbird 0.4

mozilla thunderbird 0.5

mozilla thunderbird 0.9

mozilla thunderbird 1.0

mozilla thunderbird 1.0.6

mozilla thunderbird 1.0.7

mozilla thunderbird 1.5.0.14

mozilla thunderbird 1.5.0.2

mozilla thunderbird 1.5.0.9

mozilla thunderbird 1.5.1

mozilla thunderbird 2.0.0.1

mozilla thunderbird 2.0.0.11

mozilla thunderbird 2.0.0.19

mozilla thunderbird 2.0.0.2

mozilla thunderbird 2.0.0.5

mozilla thunderbird 2.0.0.6

mozilla thunderbird 3.0.11

mozilla thunderbird 3.0.2

mozilla thunderbird 3.0.3

mozilla thunderbird 3.1

mozilla thunderbird 3.1.1

Vendor Advisories

Multiple vulnerabilities have been fixed in Firefox and Xulrunner ...
Multiple vulnerabilities have been fixed in Thunderbird ...
Several vulnerabilities have been discovered in Icedove, a mail client based on Thunderbird CVE-2011-3647 The JSSubScriptLoader does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that ...
Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey: CVE-2011-3647 moz_bug_r_a4 discovered a privilege escalation vulnerability in addon handling CVE-2011-3648 Yosuke Hasegawa discovered that incorrect handling of Shift-JIS encodings could lead to cross-site scripting CVE-2011-3650 ...
Mozilla Foundation Security Advisory 2011-46 loadSubScript unwraps XPCNativeWrapper scope parameter (192 branch) Announced November 8, 2011 Reporter moz_bug_r_a4 Impact Critical Products Firefox, Thunderbird Fixed in ...