CVE-2011-3658

Mozilla Firefox <8.0, Thunderbird <8.0, SeaMonkey <2.5 - DoS

Title source: llm

Description

The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via vectors involving removal of SVG elements.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/18847
metasploit WORKING POC NORMAL
by regenrecht · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/mozilla_nssvgvalue.rb

References (20)

Scores

EPSS 0.7588
EPSS Percentile 98.9%

Details

CWE
CWE-399
Status published
Products (3)
mozilla/firefox 8.0
mozilla/seamonkey 2.5
mozilla/thunderbird 8.0
Published Dec 21, 2011
Tracked Since Feb 18, 2026