CVE-2011-2369
30.06.2011, 16:55
Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 4.0.1 allows remote attackers to inject arbitrary web script or HTML via an SVG element containing an HTML-encoded entity.
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 4.0 |
mozilla | firefox | 4.0:beta1 |
mozilla | firefox | 4.0:beta10 |
mozilla | firefox | 4.0:beta11 |
mozilla | firefox | 4.0:beta12 |
mozilla | firefox | 4.0:beta2 |
mozilla | firefox | 4.0:beta3 |
mozilla | firefox | 4.0:beta4 |
mozilla | firefox | 4.0:beta5 |
mozilla | firefox | 4.0:beta6 |
mozilla | firefox | 4.0:beta7 |
mozilla | firefox | 4.0:beta8 |
mozilla | firefox | 4.0:beta9 |
mozilla | firefox | 4.0.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||||
firefox-3.0 |
| ||||||||||||||
firefox-3.5 |
| ||||||||||||||
seamonkey |
| ||||||||||||||
thunderbird |
| ||||||||||||||
xulrunner-1.9.2 |
| ||||||||||||||
xulrunner-2.0 |
|
References