Security Advisory

CVE-2011-2366

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-06-30 15:26:00
Last updated 2024-08-06 23:00:33
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.