CVE Vulnerabilities

CVE-2011-2362

Published: Jun 30, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 do not distinguish between cookies for two domain names that differ only in a trailing dot, which allows remote web servers to bypass the Same Origin Policy via Set-Cookie headers.

Affected Software

NameVendorStart VersionEnd Version
SeamonkeyMozilla1.0 (including)1.0 (including)
SeamonkeyMozilla1.0-alpha (including)1.0-alpha (including)
SeamonkeyMozilla1.0-beta (including)1.0-beta (including)
SeamonkeyMozilla1.0.1 (including)1.0.1 (including)
SeamonkeyMozilla1.0.2 (including)1.0.2 (including)
SeamonkeyMozilla1.0.3 (including)1.0.3 (including)
SeamonkeyMozilla1.0.4 (including)1.0.4 (including)
SeamonkeyMozilla1.0.5 (including)1.0.5 (including)
SeamonkeyMozilla1.0.6 (including)1.0.6 (including)
SeamonkeyMozilla1.0.7 (including)1.0.7 (including)
SeamonkeyMozilla1.0.8 (including)1.0.8 (including)
SeamonkeyMozilla1.0.9 (including)1.0.9 (including)
SeamonkeyMozilla1.1 (including)1.1 (including)
SeamonkeyMozilla1.1-alpha (including)1.1-alpha (including)
SeamonkeyMozilla1.1-beta (including)1.1-beta (including)
SeamonkeyMozilla1.1.1 (including)1.1.1 (including)
SeamonkeyMozilla1.1.2 (including)1.1.2 (including)
SeamonkeyMozilla1.1.3 (including)1.1.3 (including)
SeamonkeyMozilla1.1.4 (including)1.1.4 (including)
SeamonkeyMozilla1.1.5 (including)1.1.5 (including)
SeamonkeyMozilla1.1.6 (including)1.1.6 (including)
SeamonkeyMozilla1.1.7 (including)1.1.7 (including)
SeamonkeyMozilla1.1.8 (including)1.1.8 (including)
SeamonkeyMozilla1.1.9 (including)1.1.9 (including)
SeamonkeyMozilla1.1.10 (including)1.1.10 (including)
SeamonkeyMozilla1.1.11 (including)1.1.11 (including)
SeamonkeyMozilla1.1.12 (including)1.1.12 (including)
SeamonkeyMozilla1.1.13 (including)1.1.13 (including)
SeamonkeyMozilla1.1.14 (including)1.1.14 (including)
SeamonkeyMozilla1.1.15 (including)1.1.15 (including)
SeamonkeyMozilla1.1.16 (including)1.1.16 (including)
SeamonkeyMozilla1.1.17 (including)1.1.17 (including)
SeamonkeyMozilla1.1.18 (including)1.1.18 (including)
SeamonkeyMozilla1.1.19 (including)1.1.19 (including)
SeamonkeyMozilla1.5.0.8 (including)1.5.0.8 (including)
SeamonkeyMozilla1.5.0.9 (including)1.5.0.9 (including)
SeamonkeyMozilla1.5.0.10 (including)1.5.0.10 (including)
SeamonkeyMozilla2.0 (including)2.0 (including)
SeamonkeyMozilla2.0-alpha_1 (including)2.0-alpha_1 (including)
SeamonkeyMozilla2.0-alpha_2 (including)2.0-alpha_2 (including)
SeamonkeyMozilla2.0-alpha_3 (including)2.0-alpha_3 (including)
SeamonkeyMozilla2.0-beta_1 (including)2.0-beta_1 (including)
SeamonkeyMozilla2.0-beta_2 (including)2.0-beta_2 (including)
SeamonkeyMozilla2.0-rc1 (including)2.0-rc1 (including)
SeamonkeyMozilla2.0-rc2 (including)2.0-rc2 (including)
SeamonkeyMozilla2.0.1 (including)2.0.1 (including)
SeamonkeyMozilla2.0.2 (including)2.0.2 (including)
SeamonkeyMozilla2.0.3 (including)2.0.3 (including)
SeamonkeyMozilla2.0.4 (including)2.0.4 (including)
SeamonkeyMozilla2.0.5 (including)2.0.5 (including)
SeamonkeyMozilla2.0.6 (including)2.0.6 (including)
SeamonkeyMozilla2.0.7 (including)2.0.7 (including)
SeamonkeyMozilla2.0.8 (including)2.0.8 (including)
SeamonkeyMozilla2.0.9 (including)2.0.9 (including)
SeamonkeyMozilla2.0.10 (including)2.0.10 (including)
SeamonkeyMozilla2.0.11 (including)2.0.11 (including)
SeamonkeyMozilla2.0.12 (including)2.0.12 (including)
SeamonkeyMozilla2.0.13 (including)2.0.13 (including)
SeamonkeyMozilla2.0.14 (including)2.0.14 (including)
Red Hat Enterprise Linux 4RedHatfirefox-0:3.6.18-2.el4*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.12-39.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-71.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.6.18-1.el5_6*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.2.18-2.el5_6*
Red Hat Enterprise Linux 5RedHatthunderbird-0:2.0.0.24-18.el5_6*
Red Hat Enterprise Linux 6RedHatfirefox-0:3.6.18-1.el6_1*
Red Hat Enterprise Linux 6RedHatxulrunner-0:1.9.2.18-2.el6_1*
Red Hat Enterprise Linux 6RedHatthunderbird-0:3.1.11-2.el6_1*
FirefoxUbuntuhardy*
FirefoxUbuntulucid*
FirefoxUbuntumaverick*
FirefoxUbuntuupstream*
Firefox-3.0Ubuntuhardy*
Firefox-3.0Ubuntuupstream*
Firefox-3.5Ubuntuupstream*
SeamonkeyUbuntuhardy*
SeamonkeyUbuntulucid*
SeamonkeyUbuntumaverick*
SeamonkeyUbuntunatty*
SeamonkeyUbuntuupstream*
ThunderbirdUbuntuhardy*
ThunderbirdUbuntulucid*
ThunderbirdUbuntumaverick*
ThunderbirdUbuntunatty*
ThunderbirdUbuntuupstream*
Xulrunner-1.9.2Ubuntuhardy*
Xulrunner-1.9.2Ubuntulucid*
Xulrunner-1.9.2Ubuntumaverick*
Xulrunner-1.9.2Ubuntuupstream*

References