CVE-2011-3653

UnknownEPSS 1.03%

Last modified

CVE-2011-3653 is a vulnerability of currently unknown severity. Mozilla Firefox before 8.0 and Thunderbird before 8.0 on Mac OS X do not properly interact with the GPU memory behavior of a certain driver for Intel integrated GPUs, which allows remote attackers to bypass the Same Origin Policy and read image data via vectors related to WebGL textures.. EPSS estimates a 1.03% chance of exploitation in the next 30 days.

Description

Mozilla Firefox before 8.0 and Thunderbird before 8.0 on Mac OS X do not properly interact with the GPU memory behavior of a certain driver for Intel integrated GPUs, which allows remote attackers to bypass the Same Origin Policy and read image data via vectors related to WebGL textures.

Metrics

EPSS Probability
1.03%

59.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MozillaFirefox<= 7.0.1
MozillaFirefox0.1
MozillaFirefox0.2
MozillaFirefox0.3
MozillaFirefox0.4
MozillaFirefox0.5
MozillaFirefox0.6
MozillaFirefox0.6.1
MozillaFirefox0.7
MozillaFirefox0.7.1
MozillaFirefox0.8
MozillaFirefox0.9
MozillaFirefox0.9.1
MozillaFirefox0.9.2
MozillaFirefox0.9.3
MozillaFirefox0.10
MozillaFirefox0.10.1
MozillaFirefox1.0
MozillaFirefox1.0.1
MozillaFirefox1.0.2
MozillaFirefox1.0.3
MozillaFirefox1.0.4
MozillaFirefox1.0.5
MozillaFirefox1.0.6
MozillaFirefox1.0.7
MozillaFirefox1.0.8
MozillaFirefox2.0
MozillaFirefox2.0.0.1
MozillaFirefox2.0.0.2
MozillaFirefox2.0.0.3
MozillaFirefox2.0.0.4
MozillaFirefox2.0.0.5
MozillaFirefox2.0.0.6
MozillaFirefox2.0.0.7
MozillaFirefox2.0.0.8
MozillaFirefox2.0.0.9
MozillaFirefox2.0.0.10
MozillaFirefox2.0.0.11
MozillaFirefox2.0.0.12
MozillaFirefox2.0.0.13
MozillaFirefox2.0.0.14
MozillaFirefox2.0.0.15
MozillaFirefox2.0.0.16
MozillaFirefox2.0.0.17
MozillaFirefox2.0.0.18
MozillaFirefox2.0.0.19
MozillaFirefox2.0.0.20
MozillaFirefox3.0.1
MozillaFirefox3.0.2
MozillaFirefox3.0.3

Showing 50 of 205 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2011-3653?
Mozilla Firefox before 8.0 and Thunderbird before 8.0 on Mac OS X do not properly interact with the GPU memory behavior of a certain driver for Intel integrated GPUs, which allows remote attackers to bypass the Same Origin Policy and read image data via vectors related to WebGL textures.
How severe is CVE-2011-3653?
Severity scoring for CVE-2011-3653 is pending analysis. The EPSS model estimates a 1.03% probability of exploitation in the next 30 days.
How do I fix CVE-2011-3653?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2011-3653?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST