CVE-2011-2371 describes an integer overflow vulnerability in the Array.reduceRight method affecting Mozilla Firefox (before 3.6.18 and 4.x through 4.0.1), Thunderbird (before 3.1.11), and SeaMonkey (through 2.0.14). This critical flaw, rated with a CVSS score of 10.0, allows unauthenticated remote attackers to execute arbitrary code with low attack complexity. While not listed on CISA's KEV catalog, exploit modules are publicly available in Metasploit and ExploitDB, indicating a high potential for exploitation. Despite the availability of exploit code, there is no significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:1.0:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:1.0:alpha:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:* | ||
1.0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.