CVE-2011-0073

Mozilla Firefox <3.5.19 & <3.6.17, SeaMonkey <2.0.14 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2011-0073. PoCs published by Metasploit, Abysssec, regenrecht, xero, including Metasploit module exploits/windows/browser/mozilla_nstreerange.

AI-analyzed exploit summary This Metasploit module exploits a dangling pointer vulnerability in Mozilla Firefox (CVE-2011-0073) by manipulating the nsTreeRange object to achieve remote code execution. It bypasses DEP without ROP but relies on Java or is limited by ASLR on non-XP systems.

Description

Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/17520

This Metasploit module exploits a dangling pointer vulnerability in Mozilla Firefox (CVE-2011-0073) by manipulating the nsTreeRange object to achieve remote code execution. It bypasses DEP without ROP but relies on Java or is limited by ASLR on non-XP systems.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Mozilla Firefox 3.5.x <= 3.5.17, 3.6.x <= 3.6.16
No auth needed
Prerequisites: Victim uses vulnerable Firefox version · Java enabled (for ASLR bypass) or Windows XP (no ASLR)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Abysssec · remotewindows
https://www.exploit-db.com/exploits/17419

This exploit targets a use-after-free vulnerability in Mozilla Firefox <= 3.6.16 via the nsTreeSelection element. It leverages a Java ROP chain to bypass DEP/ASLR on Windows 7, achieving remote code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Mozilla Firefox <= 3.6.16
No auth needed
Prerequisites: Target running Firefox <= 3.6.16 on Windows 7 · Java installed for ROP chain
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by regenrecht, xero · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/mozilla_nstreerange.rb

This Metasploit module exploits a dangling pointer vulnerability in Mozilla Firefox's nsTreeRange object, allowing remote code execution by manipulating heap memory and bypassing DEP without ROP. It targets Firefox 3.5.x to 3.6.16 on Windows, leveraging Java or ASLR bypass techniques.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Mozilla Firefox 3.5.x to 3.6.16
No auth needed
Prerequisites: Victim must visit a malicious webpage · Java enabled or Windows XP (non-ASLR) for reliable exploitation
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2228
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14020
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2011:079
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=630919
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2235
Various Sources x_refsource_confirm
http://downloads.avaya.com/css/P8/documents/100134543
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2227
Various Sources x_refsource_confirm
http://downloads.avaya.com/css/P8/documents/100144158
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8310

Scores

EPSS 0.6998
EPSS Percentile 99.3%

Details

CWE
CWE-20
Status published
Products (47)
mozilla/firefox 3.6
mozilla/firefox 3.6.2
mozilla/firefox 3.6.3
mozilla/firefox 3.6.4
mozilla/firefox 3.6.6
mozilla/firefox 3.6.7
mozilla/firefox 3.6.8
mozilla/firefox 3.6.9
mozilla/firefox 3.6.10
mozilla/firefox 3.6.11
... and 37 more
Published May 07, 2011
Tracked Since Feb 18, 2026