CVE-2011-2378
Firefox < 3.6.20 - Remote Code Execution via Dangling Pointer Dereference
Title source: llmDescription
The appendChild function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, SeaMonkey 2.x, and possibly other products does not properly handle DOM objects, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to dereferencing of a "dangling pointer."
References (11)
Core 11
Core References
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2011:127
Vendor Advisory x_refsource_confirm
http://www.mozilla.org/security/announce/2011/mfsa2011-30.html
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=648065
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2011/dsa-2297
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00027.html
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2011/dsa-2296
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-1166.html
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00023.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-1164.html
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2011/dsa-2295
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14163
Scores
EPSS
0.0556
EPSS Percentile
91.9%
Details
CWE
CWE-94
Status
published
Products (47)
mozilla/firefox
1.0 (2 CPE variants)
mozilla/firefox
1.0.1
mozilla/firefox
1.0.2
mozilla/firefox
1.0.3
mozilla/firefox
1.0.4
mozilla/firefox
1.0.5
mozilla/firefox
1.0.6
mozilla/firefox
1.0.7
mozilla/firefox
1.0.8
mozilla/firefox
1.5 (3 CPE variants)
... and 37 more
Published
Aug 18, 2011
Tracked Since
Feb 18, 2026