VULNERABILITY INTELLIGENCE

CVE-2011-2986

CVSS score5 MEDIUM
EPSS probability1.20%
CISA KEVNot currently listed
Published2011-08-18
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:N/C:P/I:N/A:N

Description

Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used on Windows, allows remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas.

Weakness classification

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Primary references