Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-3654
HistoryNov 09, 2011 - 12:00 a.m.

CVE-2011-3654

2011-11-0900:00:00
ubuntu.com
ubuntu.com
13

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.074

Percentile

94.2%

The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0
does not properly handle links from SVG mpath elements to non-SVG elements,
which allows remote attackers to cause a denial of service (memory
corruption and application crash) or possibly execute arbitrary code via
unspecified vectors.

OSVersionArchitecturePackageVersionFilename
ubuntu11.04noarchfirefox< 8.0+build1-0ubuntu0.11.04.3UNKNOWN
ubuntu11.10noarchfirefox< 8.0+build1-0ubuntu0.11.10.3UNKNOWN
ubuntu11.10noarchthunderbird< 8.0+build1-0ubuntu0.11.10.1UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.074

Percentile

94.2%