CVE-2011-3658
Mozilla Firefox <8.0, Thunderbird <8.0, SeaMonkey <2.5 - DoS
Title source: llmDescription
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via vectors involving removal of SVG elements.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/18847
metasploit
WORKING POC
NORMAL
by regenrecht · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/mozilla_nssvgvalue.rb
References (20)
Scores
EPSS
0.7588
EPSS Percentile
98.9%
Details
CWE
CWE-399
Status
published
Products (3)
mozilla/firefox
8.0
mozilla/seamonkey
2.5
mozilla/thunderbird
8.0
Published
Dec 21, 2011
Tracked Since
Feb 18, 2026