CVE-2011-2371 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 75.7% (pctl 100)
Patch early
A public exploit exists.
Description
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via vectors involving a long JavaScript Array object.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 75.69% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-189 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-06-30 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | seamonkey |
| mozilla | thunderbird |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mozilla Firefox 4.0.1 - 'Array.reduceRight()' Remote Overflow | 2012-02-27 |
| exploit-db | Mozilla Firefox - 'Array.reduceRight()' Integer Overflow (Metasploit) (2) | 2011-10-13 |
| exploit-db | Mozilla Firefox - 'Array.reduceRight()' Integer Overflow (1) | 2011-10-12 |
References
- http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00001.html
- http://secunia.com/advisories/45002
- http://securityreason.com/securityalert/8472
- http://support.avaya.com/css/P8/documents/100144854
- http://support.avaya.com/css/P8/documents/100145333
- http://www.debian.org/security/2011/dsa-2268
- http://www.debian.org/security/2011/dsa-2269
- http://www.debian.org/security/2011/dsa-2273
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:111
- http://www.mozilla.org/security/announce/2011/mfsa2011-22.html
- http://www.redhat.com/support/errata/RHSA-2011-0885.html
- http://www.redhat.com/support/errata/RHSA-2011-0887.html
- http://www.redhat.com/support/errata/RHSA-2011-0888.html
- http://www.ubuntu.com/usn/USN-1149-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=664009
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13987
- http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00001.html
- http://secunia.com/advisories/45002
- http://securityreason.com/securityalert/8472
- http://support.avaya.com/css/P8/documents/100144854
→ the Explorer · watch your stack · NVD