
CVE-2011-2372 – Mozilla: Code installation through holding down Enter (MFSA 2011-40)
https://notcve.org/view.php?id=CVE-2011-2372
29 Sep 2011 — Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent the starting of a download in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site. Mozilla Firefox anteriores a v3.6.23 y 4.x anteriores a v6, Thunderbird anteriores a v7.0 y SeaMonkey anteriores a v2.4, no impiden la puesta en marcha de una descarga en respuesta a la pulsación de la tecla Enter, lo qu... • http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2011-2995 – Mozilla: Miscellaneous memory safety hazards (MFSA 2011-36)
https://notcve.org/view.php?id=CVE-2011-2995
29 Sep 2011 — Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Múltiples vulnerabilidades no especificadas en el motor del navegador de Mozilla Firefox anteriores a v3.6.23 y 4.x hasta v6, Thunderbird anteriores a v7.0 y SeaMonkey anteriores a v2.4, permiten a atac... • http://lists.opensuse.org/opensuse-updates/2011-10/msg00002.html •

CVE-2011-2997
https://notcve.org/view.php?id=CVE-2011-2997
29 Sep 2011 — Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Múltiples vulnerabilidades no especificadas en el motor del navegador de Mozilla Firefox anteriores a v6, Thunderbird anteriores a v7.0 y SeaMonkey anteriores a v2.4, permiten a atacantes remotos causar una denegación de servicio (c... • http://lists.opensuse.org/opensuse-updates/2011-10/msg00002.html •

CVE-2011-2999 – Mozilla: XSS via plugins and shadowed window.location object (MFSA 2011-38)
https://notcve.org/view.php?id=CVE-2011-2999
29 Sep 2011 — Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6.0, and SeaMonkey before 2.3 do not properly handle "location" as the name of a frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, a different vulnerability than CVE-2010-0170. Mozilla Firefox anteriores a v3.6.23 y v4.x hasta v5,Thunderbird anteriores a v6.0 y SeaMonkey anteriores a v2.3 no gestionan adecuadamente "Location" como el nombre de un marco, que permite a atacantes remotos evitar la "S... • http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-264: Permissions, Privileges, and Access Controls •

CVE-2011-3000 – Mozilla: Defense against multiple Location headers due to CRLF Injection (MFSA 2011-39)
https://notcve.org/view.php?id=CVE-2011-3000
29 Sep 2011 — Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values. Mozilla Firefox anterior a v3.6.23 y v4.x hasta v6, Thunderbird anteriores a v7.0, y SeaMonkey anteriores a v2.4 no gestionan adecuadamente las respuestas HTTP que contienen cabeceras... • http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.html • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2011-3001
https://notcve.org/view.php?id=CVE-2011-3001
29 Sep 2011 — Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error. Mozilla Firefox v4.x hasta v6, Thunderbird anterior a v7.0 y SeaMonkey anterior a v2.4 no impiden instalación manual de complementos (add-on) en respuesta a la presión de la tecla Enter, lo que ... • http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2011-3002
https://notcve.org/view.php?id=CVE-2011-3002
29 Sep 2011 — Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox before 7.0 and SeaMonkey before 2.4, does not validate the return value of a GrowAtomTable function call, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a memory-allocation error and a resulting buffer overflow. Almost Native Graphics Layer Engine (ANGLE), como el usado en Mozilla Firefox anteriores a v7.0 y SeaMonkey anteriores a v2.4, no valida... • http://www.mandriva.com/security/advisories?name=MDVSA-2011:141 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2011-3003
https://notcve.org/view.php?id=CVE-2011-3003
29 Sep 2011 — Mozilla Firefox before 7.0 and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unspecified WebGL test case that triggers a memory-allocation error and a resulting out-of-bounds write operation. Mozilla Firefox anteriores a v7.0 y SeaMonkey anteriores a v2.4 permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) o posiblemente ejecutar código arbitrario a través de un caso de text WebGL si... • http://www.mandriva.com/security/advisories?name=MDVSA-2011:141 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2011-3004
https://notcve.org/view.php?id=CVE-2011-3004
29 Sep 2011 — The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior. JSSubScriptLoader en Mozilla Firefox 4.x hasta la versión 6 y SeaMonkey anteriores a la 2.4 no maneja apropiadamente XPCNativeWrappers durante llamadas al método loadSubScript en un complemento, lo que fac... • http://www.mandriva.com/security/advisories?name=MDVSA-2011:141 • CWE-20: Improper Input Validation •

CVE-2011-3005
https://notcve.org/view.php?id=CVE-2011-3005
29 Sep 2011 — Use-after-free vulnerability in Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OGG headers in a .ogg file. Vulnerabilidad use-after-free en Mozilla Firefox v4.x hasta v6, Thunderbird antes de v7.0 y antes de SeaMonkey v2.4, permite a atacantes remotos causar una denegación de servicio (caída de aplicación) o posiblemente ejecutar código de su elección a tra... • http://lists.opensuse.org/opensuse-updates/2011-10/msg00002.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •