VYPR
Unrated severityNVD Advisory· Published Aug 18, 2011· Updated Jun 16, 2026

CVE-2011-2993

CVE-2011-2993

Description

The implementation of digital signatures for JAR files in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not prevent calls from unsigned JavaScript code to signed code, which allows remote attackers to bypass the Same Origin Policy and gain privileges via a crafted web site, a different vulnerability than CVE-2008-2801.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

41
  • cpe:2.3:a:mozilla:firefox:4.0:*:*:*:*:*:*:*+ 15 more
    • cpe:2.3:a:mozilla:firefox:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta10:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta11:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta12:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta6:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta7:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta8:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:4.0:beta9:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:5.0:*:*:*:*:*:*:*
    • (no CPE)range: >= 4.0, <= 5.0
  • cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:*+ 22 more
    • cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:beta_1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:beta_2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.1:alpha1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.1:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.1:alpha3:*:*:*:*:*:*
    • (no CPE)range: < 2.3
  • osv-coords2 versions
    < 128.5.1-1.1+ 1 more
    • (no CPE)range: < 128.5.1-1.1
    • (no CPE)range: < 50.1.0-1.1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.