CVE-2011-2988
Buffer overflow in an unspecified string class in the WebGL shader implementation in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long source-code block for a shader.
- Affected products
- Firefox, Seamonkey, Suse, Thunderbird
- Mozilla Firefox
- = 4.0, 4.0.1, 5.0
- Mozilla Seamonkey
- = 2.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.1, 2.2
- Mozilla Thunderbird
- ≤ 5.0
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 5.5% (92th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2011-08-18
CVE-2011-2988 at NVD
1 known exploit for CVE-2011-2988
Proof-of-concept code and exploit modules indexed by Sploitus