The glBufferData function in the WebGL implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not properly mitigate an unspecified flaw in an NVIDIA driver, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a related issue to CVE-2011-3101.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mfsa2012 34 | — | Upgrade to Mozilla Firefox ESR version 10.0.5Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 13.0 | Aug 4, 2012 | Jun 5, 2012 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.10.0 | Aug 4, 2012 | Jun 5, 2012 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 13.0Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird ESR version 10.0.5 | Aug 4, 2012 | Jun 5, 2012 |
| Redhat_linux | — | Upgrade xulrunner-debuginfoUpgrade xulrunnerUpgrade firefoxUpgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade firefox-debuginfoUpgrade xulrunner-devel | May 2, 2018 | Jun 5, 2012 |
| Ubuntu | — | Upgrade firefox | Nov 19, 2024 | Jun 5, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub