CVE-2011-3660
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger a compartment mismatch associated with the nsDOMMessageEvent::GetData function, and unknown other vectors.
- Affected products
- Firefox, Seamonkey, Suse, Thunderbird
- Mozilla Firefox
- = 4.0, 4.0.1, 5.0, 5.0.1, 6.0, 6.0.1, 6.0.2, 7.0, 7.0.1, 8.0
- Mozilla Seamonkey
- ≤ 2.5, 1.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.99, 1.1, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 1.1.9, 1.1.10, 1.1.11, 1.1.12, 1.1.13, 1.1.14, 1.1.15, 1.1.16, 1.1.17
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 4.4% (90th percentile)
- NVD status
- Modified
- Published
- 2011-12-21
CVE-2011-3660 at NVD
No indexed exploits for CVE-2011-3660 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2011-3660 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.