CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 2.6. It affects Windows, Firefox. It may be remotely exploitable.
CVE
CVE-2011-3649
Severity
LOW
CVSS
2.6
EPSS
0.95%
Windows Firefox
Original NVD Description
Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas. NOTE: this issue exists because of a CVE-2011-2986 regression.