Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-3656

Опубликовано: 02 июн. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.1

Описание

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.

РелизСтатусПримечание
devel

not-affected

11.0+build1-0ubuntu4
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [11.0+build1-0ubuntu4]]
precise

not-affected

11.0+build1-0ubuntu4
trusty

not-affected

11.0+build1-0ubuntu4
trusty/esm

DNE

trusty was not-affected [11.0+build1-0ubuntu4]
upstream

released

8.0
vivid

not-affected

11.0+build1-0ubuntu4

Показывать по

РелизСтатусПримечание
devel

not-affected

firefox only
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [firefox only]]
precise

not-affected

firefox only
trusty

not-affected

firefox only
trusty/esm

DNE

trusty was not-affected [firefox only]
upstream

not-affected

firefox only
vivid

not-affected

firefox only

Показывать по

EPSS

Процентиль: 58%
0.00371
Низкий

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

redhat
около 14 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.

CVSS3: 6.1
nvd
больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.

CVSS3: 6.1
debian
больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6 ...

github
почти 4 года назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.

EPSS

Процентиль: 58%
0.00371
Низкий

4.3 Medium

CVSS2

6.1 Medium

CVSS3