← back
CVE-2011-2371

CVE-2011-2371

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 76%
from disclosure to weapon104 days
Published on NVDJun 30
1st PoC+104d
metasploitJun 21
exploitation probability
76%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via vectors involving a long JavaScript Array object.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.