Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-0085

Опубликовано: 30 июн. 2011
Источник: debian
EPSS Низкий

Описание

Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via a crafted XUL document that dequeues the current command updater.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
iceweaselfixed3.5.19-3package
xulrunnerremovedpackage
xulrunnerfixed1.9.0.19-12lennypackage
iceweaselnot-affectedlennypackage
iceapefixed2.0.14-3package
iceapenot-affectedlennypackage
icedovefixed3.1.11-1package
icedoveend-of-lifelennypackage

Примечания

  • xulrunner in wheezy is not covered by security support

EPSS

Процентиль: 84%
0.02451
Низкий

Связанные уязвимости

ubuntu
почти 14 лет назад

Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via a crafted XUL document that dequeues the current command updater.

redhat
около 14 лет назад

Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via a crafted XUL document that dequeues the current command updater.

nvd
почти 14 лет назад

Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via a crafted XUL document that dequeues the current command updater.

github
около 3 лет назад

Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via a crafted XUL document that dequeues the current command updater.

oracle-oval
около 14 лет назад

ELSA-2011-0886: thunderbird security update (CRITICAL)

EPSS

Процентиль: 84%
0.02451
Низкий