CVE-2011-2605 PUBLISHED CVSS 4.300000190734863 MEDIUM

CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.

EPSS 0.35% · 57.0th percentile

Risk Scores

CVSS v2.0
4.300000190734863
EPSS Score
0.35%
57.0th percentile

Affected Products

VendorProductVersions
n/an/an/a
mozillathunderbird0, 0.1, 0.2
mozillafirefox3.5.11, 3.5.12, 3.5.13

Timeline

References

Open in Interactive Console →