CVE-2011-2993
Description
The implementation of digital signatures for JAR files in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not prevent calls from unsigned JavaScript code to signed code, which allows remote attackers to bypass the Same Origin Policy and gain privileges via a crafted web site, a different vulnerability than CVE-2008-2801.
Risk Information
Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.362
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Update for SeaMonkey (2.35) | Windows |
| Update for SeaMonkey (2.38) | Windows |
| Update for SeaMonkey (2.39) | Windows |
| Mozilla Firefox (63.0) | Windows |
| Mozilla Firefox (x64) (63.0) | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 4.0 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 4.0.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 5.0 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 4.0 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 4.0.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 5.0 | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-301494 | Update for SeaMonkey (2.35) |
| PATCH-301495 | Update for SeaMonkey (2.38) |
| PATCH-301496 | Update for SeaMonkey (2.39) |
| PATCH-308288 | Mozilla Firefox (63.0) |
| PATCH-308291 | Mozilla Firefox (x64) (63.0) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234