9.3
CVSSv2

CVE-2011-3655

Published: 09/11/2011 Updated: 19/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Mozilla Firefox 4.x up to and including 7.0 and Thunderbird 5.0 up to and including 7.0 perform access control without checking for use of the NoWaiverWrapper wrapper, which allows remote malicious users to gain privileges via a crafted web site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 4.0.1

mozilla firefox 4.0

mozilla firefox 5.0

mozilla firefox 5.0.1

mozilla firefox 6.0

mozilla firefox 6.0.2

mozilla firefox 6.0.1

mozilla firefox 7.0

mozilla thunderbird 5.0

mozilla thunderbird 6.0

mozilla thunderbird 6.0.1

mozilla thunderbird 6.0.2

mozilla thunderbird 7.0

Vendor Advisories

Multiple vulnerabilities have been fixed in Thunderbird ...
Multiple vulnerabilities have been fixed in Firefox ...
This update provides packages compatible with Firefox 8 ...
Mozilla Foundation Security Advisory 2011-52 Code execution via NoWaiverWrapper Announced November 8, 2011 Reporter moz_bug_r_a4 Impact Critical Products Firefox, SeaMonkey, Thunderbird Fixed in ...