CVE-2011-2980

Untrusted search path vulnerability in the ThinkPadSensor::Startup function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, allows local users to gain privileges by leveraging write access in an unspecified directory to place a Trojan horse DLL that is loaded into the running Firefox process.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
VendorProductVersion
mozillafirefox
𝑥
≤ 3.6.19
mozillafirefox
1.0
mozillafirefox
1.0:preview_release
mozillafirefox
1.0.1
mozillafirefox
1.0.2
mozillafirefox
1.0.3
mozillafirefox
1.0.4
mozillafirefox
1.0.5
mozillafirefox
1.0.6
mozillafirefox
1.0.7
mozillafirefox
1.0.8
mozillafirefox
1.5
mozillafirefox
1.5:beta1
mozillafirefox
1.5:beta2
mozillafirefox
1.5.0.1
mozillafirefox
1.5.0.2
mozillafirefox
1.5.0.3
mozillafirefox
1.5.0.4
mozillafirefox
1.5.0.5
mozillafirefox
1.5.0.6
mozillafirefox
1.5.0.7
mozillafirefox
1.5.0.8
mozillafirefox
1.5.0.9
mozillafirefox
1.5.0.10
mozillafirefox
1.5.0.11
mozillafirefox
1.5.0.12
mozillafirefox
1.5.1
mozillafirefox
1.5.2
mozillafirefox
1.5.3
mozillafirefox
1.5.4
mozillafirefox
1.5.5
mozillafirefox
1.5.6
mozillafirefox
1.5.7
mozillafirefox
1.5.8
mozillafirefox
2.0
mozillafirefox
2.0.0.1
mozillafirefox
2.0.0.2
mozillafirefox
2.0.0.3
mozillafirefox
2.0.0.4
mozillafirefox
2.0.0.5
mozillafirefox
2.0.0.6
mozillafirefox
2.0.0.7
mozillafirefox
2.0.0.8
mozillafirefox
2.0.0.9
mozillafirefox
2.0.0.10
mozillafirefox
2.0.0.11
mozillafirefox
2.0.0.12
mozillafirefox
2.0.0.13
mozillafirefox
2.0.0.14
mozillafirefox
2.0.0.15
mozillafirefox
2.0.0.16
mozillafirefox
2.0.0.17
mozillafirefox
2.0.0.18
mozillafirefox
2.0.0.19
mozillafirefox
2.0.0.20
mozillafirefox
3.0
mozillafirefox
3.0.1
mozillafirefox
3.0.2
mozillafirefox
3.0.3
mozillafirefox
3.0.4
mozillafirefox
3.0.5
mozillafirefox
3.0.6
mozillafirefox
3.0.7
mozillafirefox
3.0.8
mozillafirefox
3.0.9
mozillafirefox
3.0.10
mozillafirefox
3.0.11
mozillafirefox
3.0.12
mozillafirefox
3.0.13
mozillafirefox
3.0.14
mozillafirefox
3.0.15
mozillafirefox
3.0.16
mozillafirefox
3.0.17
mozillafirefox
3.5
mozillafirefox
3.5.1
mozillafirefox
3.5.2
mozillafirefox
3.5.3
mozillafirefox
3.5.4
mozillafirefox
3.5.5
mozillafirefox
3.5.6
mozillafirefox
3.5.7
mozillafirefox
3.5.8
mozillafirefox
3.5.9
mozillafirefox
3.5.10
mozillafirefox
3.5.11
mozillafirefox
3.5.12
mozillafirefox
3.5.13
mozillafirefox
3.5.14
mozillafirefox
3.5.15
mozillafirefox
3.5.16
mozillafirefox
3.5.17
mozillafirefox
3.5.18
mozillafirefox
3.5.19
mozillafirefox
3.6
mozillafirefox
3.6.2
mozillafirefox
3.6.3
mozillafirefox
3.6.4
mozillafirefox
3.6.6
mozillafirefox
3.6.7
mozillafirefox
3.6.8
mozillafirefox
3.6.9
mozillafirefox
3.6.10
mozillafirefox
3.6.11
mozillafirefox
3.6.12
mozillafirefox
3.6.13
mozillafirefox
3.6.14
mozillafirefox
3.6.15
mozillafirefox
3.6.16
mozillafirefox
3.6.17
mozillafirefox
3.6.18
mozillathunderbird
3.0
mozillathunderbird
3.0.1
mozillathunderbird
3.0.2
mozillathunderbird
3.0.3
mozillathunderbird
3.0.4
mozillathunderbird
3.0.5
mozillathunderbird
3.0.6
mozillathunderbird
3.0.7
mozillathunderbird
3.0.8
mozillathunderbird
3.0.9
mozillathunderbird
3.0.10
mozillathunderbird
3.0.11
mozillathunderbird
3.1
mozillathunderbird
3.1.1
mozillathunderbird
3.1.2
mozillathunderbird
3.1.3
mozillathunderbird
3.1.4
mozillathunderbird
3.1.5
mozillathunderbird
3.1.6
mozillathunderbird
3.1.7
mozillathunderbird
3.1.8
mozillathunderbird
3.1.9
mozillathunderbird
3.1.10
mozillathunderbird
3.1.11
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
natty
Fixed 6.0+build1+nobinonly-0ubuntu0.11.04.1
released
maverick
Fixed 3.6.20+build1+nobinonly-0ubuntu0.10.10.1
released
lucid
Fixed 3.6.20+build1+nobinonly-0ubuntu0.10.04.1
released
hardy
ignored
seamonkey
natty
ignored
maverick
ignored
lucid
ignored
hardy
ignored
thunderbird
natty
Fixed 3.1.13+build1+nobinonly-0ubuntu0.11.04.1
released
maverick
Fixed 3.1.13+build1+nobinonly-0ubuntu0.10.10.1
released
lucid
Fixed 3.1.13+build1+nobinonly-0ubuntu0.10.04.1
released
hardy
ignored
xulrunner-1.9.2
natty
ignored
maverick
Fixed 1.9.2.20+build1+nobinonly-0ubuntu0.10.10.1
released
lucid
Fixed 1.9.2.20+build1+nobinonly-0ubuntu0.10.04.1
released
hardy
ignored
xulrunner-2.0
natty
ignored
maverick
dne
lucid
dne
hardy
dne