VYPR
Unrated severityNVD Advisory· Published Jun 30, 2011· Updated Jun 16, 2026

CVE-2011-2369

CVE-2011-2369

Description

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 4.0.1 allows remote attackers to inject arbitrary web script or HTML via an SVG element containing an HTML-encoded entity.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

17
  • cpe:2.3:a:mozilla:firefox:4.0:*:*:*:*:*:*:*+ 14 more
    • cpe:2.3:a:mozilla:firefox:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta10:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta11:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta12:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta6:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta7:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta8:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta9:*:*:*:*:*:*
    • (no CPE)range: 4.x through 4.0.1
  • osv-coords2 versions
    < 128.5.1-1.1+ 1 more
    • (no CPE)range: < 128.5.1-1.1
    • (no CPE)range: < 50.1.0-1.1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.