Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace image.
                
            Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
        
        AV:N/AC:L/Au:N/C:N/I:N/A:P
    
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products | 
|---|---|
| Mozilla | 
 | 
| Redhat | 
 | 
Configuration 1 [-]
| 
 | 
Configuration 2 [-]
| 
 | 
Configuration 3 [-]
| 
 | 
Configuration 4 [-]
| 
 | 
| Package | CPE | Advisory | Released Date | 
|---|---|---|---|
| Red Hat Enterprise Linux 4 | |||
| firefox-0:3.6.18-2.el4 | cpe:/o:redhat:enterprise_linux:4 | RHSA-2011:0885 | 2011-06-21T00:00:00Z | 
| thunderbird-0:1.5.0.12-39.el4 | cpe:/o:redhat:enterprise_linux:4 | RHSA-2011:0887 | 2011-06-21T00:00:00Z | 
| seamonkey-0:1.0.9-71.el4 | cpe:/o:redhat:enterprise_linux:4 | RHSA-2011:0888 | 2011-06-21T00:00:00Z | 
| Red Hat Enterprise Linux 5 | |||
| firefox-0:3.6.18-1.el5_6 | cpe:/o:redhat:enterprise_linux:5 | RHSA-2011:0885 | 2011-06-21T00:00:00Z | 
| xulrunner-0:1.9.2.18-2.el5_6 | cpe:/o:redhat:enterprise_linux:5 | RHSA-2011:0885 | 2011-06-21T00:00:00Z | 
| thunderbird-0:2.0.0.24-18.el5_6 | cpe:/o:redhat:enterprise_linux:5 | RHSA-2011:0887 | 2011-06-21T00:00:00Z | 
| Red Hat Enterprise Linux 6 | |||
| firefox-0:3.6.18-1.el6_1 | cpe:/o:redhat:enterprise_linux:6 | RHSA-2011:0885 | 2011-06-21T00:00:00Z | 
| xulrunner-0:1.9.2.18-2.el6_1 | cpe:/o:redhat:enterprise_linux:6 | RHSA-2011:0885 | 2011-06-21T00:00:00Z | 
| thunderbird-0:3.1.11-2.el6_1 | cpe:/o:redhat:enterprise_linux:6 | RHSA-2011:0886 | 2011-06-21T00:00:00Z | 
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2011-06-30T16:00:00
Updated: 2024-08-06T23:00:33.620Z
Reserved: 2011-06-03T00:00:00
Link: CVE-2011-2377
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Deferred
Published: 2011-06-30T16:55:05.520
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-2377
 Redhat
                        Redhat
                     ReportizFlow
ReportizFlow