Exploitation Summary
EIP tracks 2 public exploits for CVE-2011-3659.
PoCs published by Metasploit, regenrecht, including Metasploit module exploits/windows/browser/mozilla_attribchildremoved.
AI-analyzed exploit summary This Metasploit module exploits a use-after-free vulnerability in Firefox 8/9 via the AttributeChildRemoved() function, allowing arbitrary code execution through careful memory manipulation and ROP chains.
Description
Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes.
Exploits (2)
This Metasploit module exploits a use-after-free vulnerability in Firefox 8/9 via the AttributeChildRemoved() function, allowing arbitrary code execution through careful memory manipulation and ROP chains.
This Metasploit module exploits a use-after-free vulnerability in Firefox 8/8.0.1 and 9/9.0.1 via the AttributeChildRemoved() function, leading to arbitrary code execution through carefully crafted ROP chains.