CVE-2011-3648
Mozilla Firefox <3.6.24, 4.x-7.0 & Thunderbird <3.1.6, 5.0-7.0 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 allows remote attackers to inject arbitrary web script or HTML via crafted text with Shift JIS encoding.
References (5)
Scores
EPSS
0.0034
EPSS Percentile
56.3%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
mozilla/firefox
< 3.6.23
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
... and 35 more
Timeline
Published
Nov 09, 2011
Tracked Since
Feb 18, 2026