Summary
The host is installed with Mozilla firefox/seamonkey/thunderbird and is prone to multiple vulnerabilities.
Impact
Successful exploitation will let attackers to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Impact Level: System/Application
Solution
Upgrade to Mozilla Firefox version 3.6.20 or later, For updates refer to http://www.mozilla.com/en-US/firefox/all.html
Upgrade to SeaMonkey version to 2.3 or later
http://www.mozilla.org/projects/seamonkey/
Insight
The flaws are due to
- An error in the 'event-management' implementation, which fails to select the context for script to run in.
- Improper handling of the dropping of a tab element.
- An error in 'appendChild()' function, which fails to handle DOM objects.
Affected
SeaMonkey version 2.0 through 2.2
Mozilla Firefox version before 3.6.20
Thunderbird version 3.0 through 3.1.11
References
Severity
Classification
-
CVE CVE-2011-2378, CVE-2011-2981, CVE-2011-2984 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities