Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted file. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-2372 on Mac OS X.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Apple |
|
Mozilla |
|
Configuration 1 [-]
AND |
|
No data.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T23:46:02.542Z
Reserved: 2011-09-23T00:00:00
Link: CVE-2011-3666

No data.

Status : Modified
Published: 2011-12-21T04:02:01.177
Modified: 2024-11-21T01:30:57.910
Link: CVE-2011-3666
