CVE-2011-2367

EUVD-2011-2356
The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sensitive information from GPU memory associated with an arbitrary process, or cause a denial of service (application crash), via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
4.0
mozillafirefox
4.0:beta1
mozillafirefox
4.0:beta10
mozillafirefox
4.0:beta11
mozillafirefox
4.0:beta12
mozillafirefox
4.0:beta2
mozillafirefox
4.0:beta3
mozillafirefox
4.0:beta4
mozillafirefox
4.0:beta5
mozillafirefox
4.0:beta6
mozillafirefox
4.0:beta7
mozillafirefox
4.0:beta8
mozillafirefox
4.0:beta9
mozillafirefox
4.0.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
hardy
ignored
lucid
not-affected
maverick
not-affected
natty
Fixed 5.0+build1+nobinonly-0ubuntu0.11.04.1
released
oneiric
not-affected
precise
not-affected
quantal
not-affected
firefox-3.0
hardy
ignored
lucid
dne
maverick
dne
natty
dne
oneiric
dne
precise
dne
quantal
dne
firefox-3.5
hardy
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
precise
dne
quantal
dne
seamonkey
hardy
ignored
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected
precise
dne
quantal
dne
thunderbird
hardy
ignored
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected
precise
not-affected
quantal
not-affected
xulrunner-1.9.2
hardy
ignored
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
dne
precise
dne
quantal
dne
xulrunner-2.0
hardy
dne
lucid
dne
maverick
dne
natty
ignored
oneiric
dne
precise
dne
quantal
dne
Common Weakness Enumeration