CVE-2011-3660
Summary
| CVE | CVE-2011-3660 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-12-21 04:02:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger a compartment mismatch associated with the nsDOMMessageEvent::GetData function, and unknown other vectors. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 4.0 | All | All | All |
| Application | Mozilla | Firefox | 4.0 | beta1 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta10 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta11 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta12 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta2 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta3 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta4 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta5 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta6 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta7 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta8 | All | All |
| Application | Mozilla | Firefox | 4.0 | beta9 | All | All |
| Application | Mozilla | Firefox | 4.0.1 | All | All | All |
| Application | Mozilla | Firefox | 5.0 | All | All | All |
| Application | Mozilla | Firefox | 5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 6.0 | All | All | All |
| Application | Mozilla | Firefox | 6.0.1 | All | All | All |
| Application | Mozilla | Firefox | 6.0.2 | All | All | All |
| Application | Mozilla | Firefox | 7.0 | All | All | All |
| Application | Mozilla | Firefox | 7.0.1 | All | All | All |
| Application | Mozilla | Firefox | 8.0 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | alpha | All |
| Application | Mozilla | Seamonkey | 1.0 | All | beta | All |
| Application | Mozilla | Seamonkey | 1.0 | All | dev | All |
| Application | Mozilla | Seamonkey | 1.0 | alpha | All | All |
| Application | Mozilla | Seamonkey | 1.0 | beta | All | All |
| Application | Mozilla | Seamonkey | 1.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.2 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.3 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.4 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.5 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.6 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.7 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.8 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.9 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.99 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1 | alpha | All | All |
| Application | Mozilla | Seamonkey | 1.1 | beta | All | All |
| Application | Mozilla | Seamonkey | 1.1.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.10 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.11 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.12 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.13 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.14 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.15 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.16 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.17 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.18 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.19 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.2 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.3 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.4 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.5 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.5 | 1.1.10 | All | All |
| Application | Mozilla | Seamonkey | 1.1.6 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.7 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.8 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.9 | All | All | All |
| Application | Mozilla | Seamonkey | 1.5.0.10 | All | All | All |
| Application | Mozilla | Seamonkey | 1.5.0.8 | All | All | All |
| Application | Mozilla | Seamonkey | 1.5.0.9 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_2 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_3 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | beta_1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | beta_2 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | rc1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | rc2 | All | All |
| Application | Mozilla | Seamonkey | 2.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.10 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.11 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.12 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.13 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.14 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.2 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.3 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.4 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.5 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.6 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.7 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.8 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.9 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0a1 | All | pre | All |
| Application | Mozilla | Seamonkey | 2.0a1pre | All | All | All |
| Application | Mozilla | Seamonkey | 2.1 | alpha1 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | alpha2 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | alpha3 | All | All |
| Application | Mozilla | Seamonkey | 2.3.3 | All | All | All |
| Application | Mozilla | Seamonkey | All | All | All | All |
| Application | Mozilla | Thunderbird | 5.0 | All | All | All |
| Application | Mozilla | Thunderbird | 6.0 | All | All | All |
| Application | Mozilla | Thunderbird | 6.0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 6.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 7.0 | All | All | All |
| Application | Mozilla | Thunderbird | 7.0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 8.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 694200 – Crash [@ js::mjit::ic::BaseIC::disable] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 701248 – Assertion failure: ((js::SrcNoteType)(((*(sn) >> 3) >= SRC_XDELTA) ? SRC_XDELTA : *(sn) >> 3)) == SRC_DESTRUCT, at jsopcode.cpp:3543 | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 701637 – DOM related GC | Cycle Collector Crash triggered by harfbuzz buffer overrun | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Mozilla Thunderbird Multiple Flaws Permit Remote Code Execution and Keystroke Detection - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| 700512 – Workers + Files exposes threadsafety assertions with DataOwner | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 680687 – Crash [@ nsSVGSwitchElement::FindActiveChild] after GC | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 693144 – Crash [@ js::mjit::EnterMethodJIT] with typed array and TI | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 686107 – Crash [@ JSC::MacroAssemblerCodePtr::executableAddress()] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 685186 – Assertion failure: [infer failure] Missing type for arg 1 in jsinfer.cpp | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 697255 – TM/JM: Crash [@ js_GetProperty] or [@ js::analyze::ScriptAnalysis::maybeCode] or "Assertion failure: offset < script->length," or "Assertion failure: script->code <= pc && pc < endpc," | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 685321 – Assertion failure: [infer failure] Missing type pushed 0: int, at jsinfer.cpp:341 with destructuring assignment | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 691873 – js::types::TypeCompartment::addPending can write off end of pendingArray if OOM | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 706249 – "ASSERTION: We've overflowed the mSpec buffer" in nsStandardURL::BuildNormalizedSpec | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 679986 – Assertion failure: limit >= start, at jsregexpinlines.h:274 or Crash [@ QuoteString] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| [security-announce] openSUSE-SU-2012:0007-1: important: seamonkey | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| 689892 – Assertion failure: isInterpreted(), at ../../jsfun.h:199 or Crash [@ js::gc::Cell::compartment] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Mozilla Seamonkey Multiple Flaws Permit Remote Code Execution and Keystroke Detection - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| 693143 – Crash in _cairo_dwrite_font_face_scaled_font_create | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 679494 – "compartment mismatched" when listening message event | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 688974 – Assertion failure: lastProp->hasSlot() && getSlot(lastProp->slot).isUndefined(), at jsscope.cpp:1151 | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 562442 – Crash in [@ nsPluginInstanceOwner::ReleasePluginPort(void*)] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 690376 – Crash [@ JSObject::nonNativeSetProperty] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Support / Security / Advisories / / MDVSA-2011:192 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| 682252 – YARR Assertion failure: static_cast<unsigned>(-position) <= pos (or optimized crash [@ JSC::Yarr::Interpreter::checkCharacterClass]) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 691746 – Assertion failure: JSID_IS_STRING(id) || JSID_IS_INT(id), at jswatchpoint.cpp:207 | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| MFSA 2011-53: Miscellaneous memory safety hazards (rv:9.0) | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| Mozilla Firefox Multiple Flaws Permit Remote Code Execution and Keystroke Detection - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [security-announce] openSUSE-SU-2012:0039-1: important: seamonkey | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| osvdb.org/77952 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 688364 – compartment mismatch when sharing with F1 | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 696579 – carefully chosen values of kernelUnitLength can cause lighting filters to overwrite memory they don't own | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.