Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2011-2992

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Mozilla Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。 Mozilla Firefox 4.x至5版本的浏览器引擎中的Ogg阅读器中存在缓冲区溢出漏洞。远程攻击者可借助未明向量导致拒绝服务(内存破坏和应用程序崩溃)或者可能执行任意代码。

AI Predicted 6.8 Difficulty: Moderate EPSS 3.62% · P89
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2011-2992

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The Ogg reader in the browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, Thunderbird before 6, and possibly other products allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Mozilla Firefox Ogg阅读器缓冲区溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mozilla Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。 Mozilla Firefox 4.x至5版本的浏览器引擎中的Ogg阅读器中存在缓冲区溢出漏洞。远程攻击者可借助未明向量导致拒绝服务(内存破坏和应用程序崩溃)或者可能执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2011-2992

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-2992

登录查看更多情报信息。

Vendor Advisories for CVE-2011-2992 (6)

Mailing List Discussions for CVE-2011-2992 (1)

Same Patch Batch · n/a · 2011-08-18 · 30 CVEs total

CVE-2011-1625 Cisco IOS竞争条件漏洞
CVE-2011-2993 Mozilla Firefox未签名脚本安全策略绕过漏洞
CVE-2011-2991 Mozilla Firefox浏览器引擎缓冲区溢出漏洞
CVE-2011-2990 Mozilla Firefox内容安全策略信任管理漏洞
CVE-2011-2989 Mozilla Firefox浏览器引擎WebGL缓冲区溢出漏洞
CVE-2011-2988 Mozilla Firefox WebGL着色器未明字符串缓冲区溢出漏洞
CVE-2011-2987 Mozilla Firefox WebGL实现ANGLE堆缓冲区溢出漏洞
CVE-2011-2986 Mozilla Firefox Direct2D API同源策略绕过信息泄露漏洞
CVE-2011-2985 Mozilla Firefox浏览器引擎多个未明安全漏洞
CVE-2011-2984 Mozilla Firefox标签元素任意JavaScript代码执行漏洞
CVE-2011-2983 Mozilla Firefox RegExp.input属性同源策略绕过漏洞
CVE-2011-2982 Mozilla Firefox浏览器引擎多个未明安全漏洞
CVE-2011-2981 Mozilla Firefox event-management实现同源策略绕过漏洞
CVE-2011-2980 Mozilla Firefox ThinkPadSensor::Startup函数不可信搜索路径漏洞
CVE-2011-2378 Mozilla Firefox appendChild函数任意代码执行漏洞
CVE-2011-2733 EMC Adaptive Authentication On-Premise重放安全限制绕过漏洞
CVE-2011-1624 Cisco IOS SSH2会话拒绝服务漏洞
CVE-2011-0084 Mozilla Firefox SVGTextElement.getCharNumAtPosition函数任意代码执行漏洞
CVE-2011-2955 RealNetworks RealPlayer释放后使用漏洞
CVE-2011-2954 RealNetworks RealPlayer AutoUpdate功能释放后使用漏洞

Showing top 20 of 30 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2011-2992

No comments yet


Leave a comment