4.3
CVSSv2

CVE-2011-3648

Published: 09/11/2011 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Mozilla Firefox prior to 3.6.24 and 4.x up to and including 7.0 and Thunderbird prior to 3.1.6 and 5.0 up to and including 7.0 allows remote malicious users to inject arbitrary web script or HTML via crafted text with Shift JIS encoding.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.6

mozilla firefox 3.6.9

mozilla firefox 3.6.10

mozilla firefox 3.6.17

mozilla firefox 3.6.18

mozilla firefox 3.6.19

mozilla firefox 3.5.14

mozilla firefox 3.5.12

mozilla firefox 3.5.2

mozilla firefox 3.5.5

mozilla firefox 3.0.6

mozilla firefox 3.0.3

mozilla firefox 3.0.17

mozilla firefox 3.0.4

mozilla firefox 3.6.2

mozilla firefox 3.6.3

mozilla firefox 3.6.11

mozilla firefox 3.6.12

mozilla firefox 3.6.20

mozilla firefox 3.6.21

mozilla firefox 3.5.13

mozilla firefox 3.5.9

mozilla firefox 3.5.1

mozilla firefox 3.5.6

mozilla firefox 3.0.5

mozilla firefox 3.0

mozilla firefox 3.0.13

mozilla firefox 3.0.7

mozilla firefox 2.0.0.19

mozilla firefox 2.0.0.13

mozilla firefox 3.6.7

mozilla firefox 3.6.8

mozilla firefox 3.6.15

mozilla firefox 3.6.16

mozilla firefox 3.5.10

mozilla firefox 3.5.15

mozilla firefox 3.5.8

mozilla firefox 3.5.4

mozilla firefox 3.0.14

mozilla firefox 3.0.1

mozilla firefox 3.0.10

mozilla firefox 3.0.8

mozilla firefox 3.0.9

mozilla firefox 3.0.2

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.9

mozilla firefox 2.0.0.7

mozilla firefox 2.0

mozilla firefox 2.0.0.3

mozilla firefox 2.0.0.2

mozilla firefox 1.0

mozilla firefox 1.0.3

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.5

mozilla firefox 1.5.0.10

mozilla firefox 1.5.3

mozilla firefox 1.5.0.7

mozilla firefox 1.5

mozilla firefox 0.10.1

mozilla firefox 0.9.1

mozilla firefox 0.9

mozilla firefox 0.3

mozilla firefox 3.6.4

mozilla firefox 3.6.6

mozilla firefox 3.6.13

mozilla firefox 3.6.14

mozilla firefox 3.6.22

mozilla firefox

mozilla firefox 3.5.3

mozilla firefox 3.5.11

mozilla firefox 3.5.7

mozilla firefox 3.5

mozilla firefox 3.0.11

mozilla firefox 3.0.12

mozilla firefox 3.0.15

mozilla firefox 3.0.16

mozilla firefox 2.0.0.20

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.5

mozilla firefox 2.0.0.4

mozilla firefox 1.0.1

mozilla firefox 1.0.6

mozilla firefox 1.0.8

mozilla firefox 1.5.0.1

mozilla firefox 1.5.0.9

mozilla firefox 1.5.0.6

mozilla firefox 0.10

mozilla firefox 0.8

mozilla firefox 0.7

mozilla firefox 0.7.1

mozilla firefox 0.2

mozilla firefox 2.0.0.17

mozilla firefox 2.0.0.10

mozilla firefox 2.0.0.11

mozilla firefox 1.4.1

mozilla firefox 1.0.4

mozilla firefox 1.0.7

mozilla firefox 1.5.0.11

mozilla firefox 1.5.0.12

mozilla firefox 1.5.2

mozilla firefox 1.5.0.8

mozilla firefox 1.5.7

mozilla firefox 1.5.6

mozilla firefox 1.5.5

mozilla firefox 0.6.1

mozilla firefox 0.9.2

mozilla firefox 0.6

mozilla firefox 0.1

mozilla firefox 2.0.0.12

mozilla firefox 2.0.0.15

mozilla firefox 2.0.0.18

mozilla firefox 2.0.0.6

mozilla firefox 2.0.0.1

mozilla firefox 2.0.0.16

mozilla firefox 1.0.2

mozilla firefox 1.0.5

mozilla firefox 1.5.0.2

mozilla firefox 1.5.0.3

mozilla firefox 1.5.4

mozilla firefox 1.5.1

mozilla firefox 1.8

mozilla firefox 1.5.8

mozilla firefox 0.9.3

mozilla firefox 0.4

mozilla firefox 0.5

mozilla thunderbird 0.1

mozilla thunderbird 0.2

mozilla thunderbird 0.7.3

mozilla thunderbird 0.8

mozilla thunderbird 1.0.5

mozilla thunderbird 1.5.0.11

mozilla thunderbird 1.5.0.12

mozilla thunderbird 1.5.0.13

mozilla thunderbird 1.5.0.7

mozilla thunderbird 1.5.0.8

mozilla thunderbird 2.0

mozilla thunderbird 2.0.0.0

mozilla thunderbird 2.0.0.16

mozilla thunderbird 2.0.0.17

mozilla thunderbird 2.0.0.18

mozilla thunderbird 2.0.0.3

mozilla thunderbird 2.0.0.4

mozilla thunderbird 3.0.1

mozilla thunderbird 3.0.10

mozilla thunderbird 3.0.8

mozilla thunderbird 3.0.9

mozilla thunderbird 3.1.4

mozilla thunderbird

mozilla thunderbird 0.7.1

mozilla thunderbird 0.7.2

mozilla thunderbird 1.0.3

mozilla thunderbird 1.0.4

mozilla thunderbird 1.5.0.1

mozilla thunderbird 1.5.0.10

mozilla thunderbird 1.5.0.5

mozilla thunderbird 1.5.0.6

mozilla thunderbird 1.7.1

mozilla thunderbird 1.7.3

mozilla thunderbird 2.0.0.14

mozilla thunderbird 2.0.0.15

mozilla thunderbird 2.0.0.22

mozilla thunderbird 2.0.0.23

mozilla thunderbird 2.0.0.9

mozilla thunderbird 3.0

mozilla thunderbird 3.0.5

mozilla thunderbird 3.0.6

mozilla thunderbird 3.0.7

mozilla thunderbird 3.1.2

mozilla thunderbird 3.1.3

mozilla thunderbird 0.6

mozilla thunderbird 0.7

mozilla thunderbird 1.0.1

mozilla thunderbird 1.0.2

mozilla thunderbird 1.0.8

mozilla thunderbird 1.5

mozilla thunderbird 1.5.0.3

mozilla thunderbird 1.5.0.4

mozilla thunderbird 1.5.2

mozilla thunderbird 2.0.0.12

mozilla thunderbird 2.0.0.13

mozilla thunderbird 2.0.0.20

mozilla thunderbird 2.0.0.21

mozilla thunderbird 2.0.0.7

mozilla thunderbird 2.0.0.8

mozilla thunderbird 3.0.3

mozilla thunderbird 3.0.4

mozilla thunderbird 3.1.10

mozilla thunderbird 3.1.11

mozilla thunderbird 0.3

mozilla thunderbird 0.4

mozilla thunderbird 0.5

mozilla thunderbird 0.9

mozilla thunderbird 1.0

mozilla thunderbird 1.0.6

mozilla thunderbird 1.0.7

mozilla thunderbird 1.5.0.14

mozilla thunderbird 1.5.0.2

mozilla thunderbird 1.5.0.9

mozilla thunderbird 1.5.1

mozilla thunderbird 2.0.0.1

mozilla thunderbird 2.0.0.11

mozilla thunderbird 2.0.0.19

mozilla thunderbird 2.0.0.2

mozilla thunderbird 2.0.0.5

mozilla thunderbird 2.0.0.6

mozilla thunderbird 3.0.11

mozilla thunderbird 3.0.2

mozilla thunderbird 3.1

mozilla thunderbird 3.1.1

mozilla firefox 4.0

mozilla firefox 6.0

mozilla firefox 6.0.1

mozilla firefox 4.0.1

mozilla firefox 5.0

mozilla firefox 5.0.1

mozilla firefox 6.0.2

mozilla firefox 7.0

mozilla thunderbird 6.0.2

mozilla thunderbird 6.0.1

mozilla thunderbird 5.0

mozilla thunderbird 6.0

mozilla thunderbird 7.0

Vendor Advisories

Multiple vulnerabilities have been fixed in Firefox and Xulrunner ...
Multiple vulnerabilities have been fixed in Thunderbird ...
Multiple vulnerabilities have been fixed in Firefox ...
Multiple vulnerabilities have been fixed in Thunderbird ...
This update provides packages compatible with Firefox 8 ...
Several vulnerabilities have been discovered in Icedove, a mail client based on Thunderbird CVE-2011-3647 The JSSubScriptLoader does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that ...
Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey: CVE-2011-3647 moz_bug_r_a4 discovered a privilege escalation vulnerability in addon handling CVE-2011-3648 Yosuke Hasegawa discovered that incorrect handling of Shift-JIS encodings could lead to cross-site scripting CVE-2011-3650 ...
Mozilla Foundation Security Advisory 2011-47 Potential XSS against sites using Shift-JIS Announced November 8, 2011 Reporter Yosuke Hasegawa Impact High Products Firefox, SeaMonkey, Thunderbird Fixed in ...