peter bassill · operator
$ cve CVE-2011-2371 JSON

CVE-2011-2371 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 75.7% (pctl 100)

Patch early

A public exploit exists.

Description

Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via vectors involving a long JavaScript Array object.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS75.69% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-189
On CISA KEVno
Public exploityes
Published2011-06-30
Last modified2026-06-16

Affected (3)

VendorProduct
mozillafirefox
mozillaseamonkey
mozillathunderbird

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD