CVE-2011-2370 Information
Feb 14, 2021
cve
Description
Mozilla Firefox before 5.0 does not properly enforce the whitelist for the xpinstall functionality which allows remote attackers to trigger an installation dialog for a (1) add-on or (2) theme via unspecified vectors.
Reference
http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00001.html http://www.mozilla.org/security/announce/2011/mfsa2011-28.html https://bugzilla.mozilla.org/show_bug.cgi?id=645699 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A14278
Share on: