VULNERABILITY INTELLIGENCE
CVE-2011-3000
CVSS score4.3 MEDIUM
EPSS probability2.02%
CISA KEVNot currently listed
Published2011-09-29
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Description
Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.
Weakness classification
- CWE-94: Improper Control of Generation of Code ('Code Injection')