Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted file. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-2372 on Mac OS X.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mfsa2011 59 | — | Upgrade to Mozilla Firefox version 3.6.25 | Jun 14, 2012 | Dec 20, 2011 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 3.1.17 | Feb 22, 2012 | Dec 20, 2011 |
| Suse | — | Upgrade mozilla-xulrunner192-translationsUpgrade mozilla-xulrunner192-32bitUpgrade mozilla-xulrunner192-translations-32bitUpgrade mozilla-xulrunner192Upgrade mozilla-xulrunner192-develUpgrade mozilla-xulrunner192-gnomeUpgrade mozilla-xulrunner192-x86Upgrade mozilla-xulrunner192-gnome-32bit | Dec 12, 2013 | Jul 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub