Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-2984

Опубликовано: 18 авг. 2011
Источник: debian

Описание

Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
icedovefixed3.1.12-1package
icedoveend-of-lifelennypackage
xulrunnerremovedpackage
xulrunnernot-affectedlennypackage
iceweaselfixed6.0-1package
iceweaselnot-affectedlennypackage
iceapefixed2.0.14-5package
iceapenot-affectedlennypackage

Примечания

  • xulrunner in wheezy is not covered by security support

Связанные уязвимости

ubuntu
почти 14 лет назад

Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.

redhat
почти 14 лет назад

Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.

nvd
почти 14 лет назад

Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.

github
около 3 лет назад

Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.

oracle-oval
почти 14 лет назад

ELSA-2011-1164: firefox security update (CRITICAL)