Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-2367 | First vendor Publication | 2011-06-30 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.4 | Attack Range | Network |
Cvss Impact Score | 4.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sensitive information from GPU memory associated with an arbitrary process, or cause a denial of service (application crash), via unspecified vectors. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2367 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-264 | Permissions, Privileges, and Access Controls |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:14302 | |||
Oval ID: | oval:org.mitre.oval:def:14302 | ||
Title: | The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sensitive information from GPU memory associated with an arbitrary process, or cause a denial of service (application crash), via unspecified vectors. | ||
Description: | The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sensitive information from GPU memory associated with an arbitrary process, or cause a denial of service (application crash), via unspecified vectors. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2011-2367 | Version: | 11 |
Platform(s): | Microsoft Windows 7 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows Server 2003 Microsoft Windows XP Microsoft Windows 2000 | Product(s): | Mozilla Firefox |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2011-08-18 | Name : SuSE Update for MozillaFirefox,MozillaThunderbird SUSE-SA:2011:028 File : nvt/gb_suse_2011_028.nasl |
2011-08-03 | Name : FreeBSD Ports: firefox File : nvt/freebsd_firefox57.nasl |
2011-07-07 | Name : Mozilla Firefox Multiple Vulnerabilities July-11 (Windows) File : nvt/gb_mozilla_firefox_mult_vuln_win_jul11.nasl |
2011-06-24 | Name : Ubuntu Update for firefox USN-1157-1 File : nvt/gb_ubuntu_USN_1157_1.nasl |
2011-06-24 | Name : Ubuntu Update for mozvoikko USN-1157-2 File : nvt/gb_ubuntu_USN_1157_2.nasl |
2011-06-24 | Name : Ubuntu Update for firefox USN-1157-3 File : nvt/gb_ubuntu_USN_1157_3.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
73190 | Mozilla Multiple Products WebGL Out-of-bounds Read GPU Processes Information ... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2011-08-17 | Name : The remote Windows host contains a web browser that may be affected by multip... File : seamonkey_22.nasl - Type : ACT_GATHER_INFO |
2011-06-24 | Name : The remote Mac OS X host contains a web browser that is affected by multiple ... File : macosx_firefox_5_0.nasl - Type : ACT_GATHER_INFO |
2011-06-24 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-1157-3.nasl - Type : ACT_GATHER_INFO |
2011-06-23 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-1157-1.nasl - Type : ACT_GATHER_INFO |
2011-06-23 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-1157-2.nasl - Type : ACT_GATHER_INFO |
2011-06-21 | Name : The remote Windows host contains a web browser that is affected by multiple v... File : mozilla_firefox_50.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:04:48 |
|
2024-11-28 12:25:59 |
|
2024-08-02 12:16:45 |
|
2024-08-02 01:04:45 |
|
2024-02-02 01:16:16 |
|
2024-02-01 12:04:39 |
|
2023-09-05 12:15:14 |
|
2023-09-05 01:04:31 |
|
2023-09-02 12:15:19 |
|
2023-09-02 01:04:35 |
|
2023-08-12 12:18:29 |
|
2023-08-12 01:04:36 |
|
2023-08-11 12:15:23 |
|
2023-08-11 01:04:44 |
|
2023-08-06 12:14:47 |
|
2023-08-06 01:04:36 |
|
2023-08-04 12:14:52 |
|
2023-08-04 01:04:37 |
|
2023-07-14 12:14:51 |
|
2023-07-14 01:04:35 |
|
2023-03-29 01:16:45 |
|
2023-03-28 12:04:41 |
|
2022-10-11 12:13:14 |
|
2022-10-11 01:04:21 |
|
2021-05-04 12:14:37 |
|
2021-04-22 01:15:56 |
|
2020-05-23 00:28:50 |
|
2017-09-19 09:24:30 |
|
2016-04-26 20:50:17 |
|
2014-02-17 11:03:01 |
|
2013-05-10 23:02:14 |
|