CVE-2011-2984: Code Injection
Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2984?
The severity of CVE-2011-2984 is rated as critical, allowing attackers to execute arbitrary JavaScript with chrome privileges.
How do I fix CVE-2011-2984?
To fix CVE-2011-2984, update your Mozilla Firefox, SeaMonkey, or Thunderbird to the latest versions that contain the patch.
Which versions are affected by CVE-2011-2984?
CVE-2011-2984 affects Mozilla Firefox versions prior to 3.6.20, SeaMonkey 2.x, and Thunderbird versions before 3.1.12.
What types of attacks are possible with CVE-2011-2984?
CVE-2011-2984 allows attackers to drop tab elements, potentially leading to cross-site scripting (XSS) attacks.
Are there any workarounds for CVE-2011-2984?
No effective workarounds are recommended for CVE-2011-2984; updating to a secure version is the only solution.