CVE-2011-2986
N/A
N/A
Summary
Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used on Windows, allows remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.mozilla.org/security/announce/2011/mfsa2011-31.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14497
- https://bugzilla.mozilla.org/show_bug.cgi?id=655836
- http://www.mozilla.org/security/announce/2011/mfsa2011-33.html
- http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00023.html
- http://secunia.com/advisories/49055
- http://www.mozilla.org/security/announce/2011/mfsa2011-29.html
References
- http://www.mozilla.org/security/announce/2011/mfsa2011-31.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14497
- https://bugzilla.mozilla.org/show_bug.cgi?id=655836
- http://www.mozilla.org/security/announce/2011/mfsa2011-33.html
- http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00023.html
- http://secunia.com/advisories/49055
- http://www.mozilla.org/security/announce/2011/mfsa2011-29.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.