Lucene search

K
nessusTenable9377.PRM
HistoryJun 24, 2016 - 12:00 a.m.

Mozilla Firefox < 3.6.24 Multiple Vulnerabilities

2016-06-2400:00:00
Tenable
www.tenable.com
9

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.011

Percentile

84.3%

Versions of Firefox earlier than 3.6.24 are potentially affected by multiple vulnerabilities :

  • A flaw exists within the ‘JSSubScriptLoader’ that incorrectly unwraps ‘XPCNativeWrappers’. By tricking a user into installing a malicious plug-in, an attacker could exploit this issue to execute arbitrary code. (CVE-2011-3647)
  • Certain invalid sequences are not handled properly in ‘Shift-JIS’ encoding and can allow cross-site scripting (XSS) attacks. (CVE-2011-3648)
  • Profiling JavaScript files with many functions can cause the application to crash. It may be possible to trigger this behavior even when the debugging APIs are not being used. (CVE-2011-3650)
Binary data 9377.prm

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.011

Percentile

84.3%