Lucene search

K
cve[email protected]CVE-2011-3649
HistoryNov 09, 2011 - 11:55 a.m.

CVE-2011-3649

2011-11-0911:55:03
CWE-200
web.nvd.nist.gov
35
cve-2011-3649
mozilla firefox
thunderbird
direct2d
d2d
same origin policy
cve-2011-2986

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

AI Score

9.2

Confidence

High

EPSS

0.005

Percentile

77.4%

Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas. NOTE: this issue exists because of a CVE-2011-2986 regression.

Affected configurations

NVD
Node
mozillafirefoxMatch7.0
OR
mozillathunderbirdMatch7.0
AND
microsoftwindows
VendorProductVersionCPE
mozillathunderbird7.0cpe:/a:mozilla:thunderbird:7.0:::
mozillafirefox7.0cpe:/a:mozilla:firefox:7.0:::

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

AI Score

9.2

Confidence

High

EPSS

0.005

Percentile

77.4%