CVE-2011-3232
YARR, as used in Mozilla Firefox before 7.0, Thunderbird before 7.0, and SeaMonkey before 2.4, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript.
- Affected products
- Firefox, Safari, Seamonkey, Suse, Thunderbird
- Mozilla Firefox
- ≤ 3.6.22, 3.6, 3.6.2, 3.6.3, 3.6.4, 3.6.6, 3.6.7, 3.6.8, 3.6.9, 3.6.10, 3.6.11, 3.6.12, 3.6.13, 3.6.14, 3.6.15, 3.6.16, 3.6.17, 3.6.18, 3.6.19, 3.6.20, 3.6.21
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 5.0% (91th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2011-09-29
CVE-2011-3232 at NVD
1 known exploit for CVE-2011-3232
Proof-of-concept code and exploit modules indexed by Sploitus