Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2011-3001

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Mozilla Firefox是美国Mozilla基金会的一款开源Web浏览器。 Mozilla Firefox 存在权限许可和访问控制问题漏洞,该漏洞源于 Mozilla Firefox 4.x 到 6、7.0 之前的 Thunderbird 和 2.4 之前的 SeaMonkey 不会阻止手动附加安装以响应按住 Enter 键,这允许用户辅助的远程攻击者通过精心设计的网络绕过预期的访问限制触发未指定内部错误的站点。

AI Predicted 6.1 Difficulty: Easy EPSS 1.47% · P72
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2011-3001

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Mozilla Firefox 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mozilla Firefox是美国Mozilla基金会的一款开源Web浏览器。 Mozilla Firefox 存在权限许可和访问控制问题漏洞,该漏洞源于 Mozilla Firefox 4.x 到 6、7.0 之前的 Thunderbird 和 2.4 之前的 SeaMonkey 不会阻止手动附加安装以响应按住 Enter 键,这允许用户辅助的远程攻击者通过精心设计的网络绕过预期的访问限制触发未指定内部错误的站点。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2011-3001

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-3001

登录查看更多情报信息。

Vendor Advisories for CVE-2011-3001 (7)

Mailing List Discussions for CVE-2011-3001 (2)

Same Patch Batch · n/a · 2011-09-29 · 14 CVEs total

CVE-2011-2372 Mozilla Firefox/Thunderbird/SeaMonkey权限许可和访问控制漏洞
CVE-2011-2995 Mozilla Firefox/Thunderbird/SeaMonkey未明安全漏洞
CVE-2011-2996 Mozilla Firefox API插件未明安全漏洞
CVE-2011-2997 Mozilla Firefox/Thunderbird/SeaMonkey未明安全漏洞
CVE-2011-2999 Mozilla Firefox/Thunderbird/SeaMonkey权限许可和访问控制漏洞
CVE-2011-3000 Mozilla Firefox/Thunderbird/SeaMonke代码注入漏洞
CVE-2011-3002 Mozilla Firefox/SeaMonkey缓冲区溢出漏洞
CVE-2011-3003 Mozilla Firefox/SeaMonkey缓冲区溢出漏洞
CVE-2011-3004 Mozilla Firefox/SeaMonkey/输入验证漏洞
CVE-2011-3005 Mozilla Firefox/Thunderbird/SeaMonkey .ogg文件缓冲区溢出漏洞
CVE-2011-3232 Mozilla Firefox/Thunderbird/SeaMonkey YARR代码注入漏洞
CVE-2011-3504 FFmpeg代码注入漏洞
CVE-2011-3866 Mozilla Firefox/SeaMonkey权限许可和访问控制漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2011-3001

No comments yet


Leave a comment