CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2011-2372 Permissions, Privileges, and Access Controls vulnerability
3.5
Firefox web browser
Solaris 11
11/11 SRU 3
Solaris 10
Contact Support
CVE-2011-2995 Denial of Service (DoS) vulnerability
10.0
CVE-2011-2997 Denial of Service (DoS) vulnerability
10.0
CVE-2011-3000 Improper Control of Generation of Code ('Code Injection') vulnerability
4.3
CVE-2011-3001 Permissions, Privileges, and Access Controls vulnerability
4.3
CVE-2011-3002 Denial of Service (DoS) vulnerability
9.3
CVE-2011-3003 Denial of Service (DoS) vulnerability
10.0
CVE-2011-3004 Improper Input Validation vulnerability
4.3
CVE-2011-3005 Denial of Service (DoS) vulnerability
9.3
CVE-2011-3232 Improper Control of Generation of Code ('Code Injection') vulnerability
9.3
CVE-2011-3648 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability
4.3
CVE-2011-3650 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability
9.3
CVE-2011-3651 Denial of Service (DoS) vulnerability
10.0
CVE-2011-3652 Denial of Service (DoS) vulnerability
10.0
CVE-2011-3654 Denial of Service (DoS) vulnerability
10.0
CVE-2011-3655 Improper Control of Generation of Code ('Code Injection') vulnerability
9.3
This notification describes vulnerabilities fixed in third-party components that are included in Sun's product distribution.Information about vulnerabilities affecting Oracle Sun products can be found on Oracle Critical Patch Updates and Security Alerts page.