CVE-2011-2996: Mozilla Firefox

High severity, CVSS 10.0. EPSS: 4.5% chance of exploitation in the next 30 days.

Unspecified vulnerability in the plugin API in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

Affected products

  • Mozilla Firefox: version 3.6 only; version 3.6.2 only; version 3.6.3 only; version 3.6.4 only; version 3.6.6 only; version 3.6.7 only; …

Published 2011-09-29. Last modified 2026-06-16.