CVE Vulnerabilities

CVE-2011-3001

Published: Sep 29, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla4.0 (including)4.0 (including)
FirefoxMozilla4.0-beta1 (including)4.0-beta1 (including)
FirefoxMozilla4.0-beta10 (including)4.0-beta10 (including)
FirefoxMozilla4.0-beta11 (including)4.0-beta11 (including)
FirefoxMozilla4.0-beta12 (including)4.0-beta12 (including)
FirefoxMozilla4.0-beta2 (including)4.0-beta2 (including)
FirefoxMozilla4.0-beta3 (including)4.0-beta3 (including)
FirefoxMozilla4.0-beta4 (including)4.0-beta4 (including)
FirefoxMozilla4.0-beta5 (including)4.0-beta5 (including)
FirefoxMozilla4.0-beta6 (including)4.0-beta6 (including)
FirefoxMozilla4.0-beta7 (including)4.0-beta7 (including)
FirefoxMozilla4.0-beta8 (including)4.0-beta8 (including)
FirefoxMozilla4.0-beta9 (including)4.0-beta9 (including)
FirefoxMozilla4.0.1 (including)4.0.1 (including)
FirefoxMozilla5.0 (including)5.0 (including)
FirefoxMozilla6.0 (including)6.0 (including)
FirefoxUbuntudevel*
FirefoxUbuntuhardy*
FirefoxUbuntunatty*
FirefoxUbuntuupstream*

References