VulnerabilityModified
CVE-2011-2598
The WebGL implementation in Mozilla Firefox 4.x allows remote attackers to obtain screenshots of the windows of arbitrary desktop applications via vectors involving an SVG filter, an IFRAME element, and uninitialized data in graphics memory.
MEDIUM 4.3EPSS 1.30%
Does this matter?
Lower severity and a low EPSS score (1.30%). Track it; it rarely justifies an emergency change on its own.
Description
The WebGL implementation in Mozilla Firefox 4.x allows remote attackers to obtain screenshots of the windows of arbitrary desktop applications via vectors involving an SVG filter, an IFRAME element, and uninitialized data in graphics memory.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- mozilla/firefox
- Source
- cve@mitre.org
References
- http://blog.mozilla.com/security/2011/06/16/webgl-graphics-memory-stealing-issue/
- http://www.contextis.com/resources/blog/webgl2/Exploit
- http://www.securityfocus.com/bid/48319
- http://www.theregister.co.uk/2011/06/16/webgl_security_threats_redux/
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14207
- http://blog.mozilla.com/security/2011/06/16/webgl-graphics-memory-stealing-issue/
- http://www.contextis.com/resources/blog/webgl2/Exploit
- http://www.securityfocus.com/bid/48319
- http://www.theregister.co.uk/2011/06/16/webgl_security_threats_redux/
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14207
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.