10
CVSSv2

CVE-2011-2378

Published: 18/08/2011 Updated: 19/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The appendChild function in Mozilla Firefox prior to 3.6.20, Thunderbird 3.x prior to 3.1.12, SeaMonkey 2.x, and possibly other products does not properly handle DOM objects, which allows remote malicious users to execute arbitrary code via unspecified vectors that lead to dereferencing of a "dangling pointer."

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.5.1

mozilla firefox 3.5.2

mozilla firefox 3.5.9

mozilla firefox 3.5.8

mozilla firefox 3.0.12

mozilla firefox 3.0.11

mozilla firefox 3.0.3

mozilla firefox 3.0.2

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.9

mozilla firefox 2.0.0.7

mozilla firefox 2.0

mozilla firefox 1.5

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.10

mozilla firefox 1.5.0.6

mozilla firefox 1.5.0.7

mozilla firefox 1.0.3

mozilla firefox 1.0.2

mozilla firefox 3.5.11

mozilla firefox 3.5.12

mozilla firefox 3.6.12

mozilla firefox 3.6.2

mozilla firefox 3.6.9

mozilla firefox 3.6.13

mozilla firefox 3.6.18

mozilla firefox

mozilla firefox 3.5.7

mozilla firefox 3.5.10

mozilla firefox 3.0.14

mozilla firefox 3.0.13

mozilla firefox 3.0.5

mozilla firefox 3.0.4

mozilla firefox 2.0.0.19

mozilla firefox 2.0.0.20

mozilla firefox 2.0.0.15

mozilla firefox 2.0.0.13

mozilla firefox 2.0.0.2

mozilla firefox 2.0.0.1

mozilla firefox 1.5.0.12

mozilla firefox 1.5.0.1

mozilla firefox 1.5.0.8

mozilla firefox 1.5.0.9

mozilla firefox 1.0.1

mozilla firefox 1.0

mozilla firefox 1.0.8

mozilla firefox 3.5.17

mozilla firefox 3.6.4

mozilla firefox 3.6

mozilla firefox 3.6.11

mozilla firefox 3.6.10

mozilla firefox 3.6.16

mozilla firefox 3.6.17

mozilla firefox 3.5.5

mozilla firefox 3.5.6

mozilla firefox 3.0.16

mozilla firefox 3.0.15

mozilla firefox 3.0.8

mozilla firefox 3.0.7

mozilla firefox 3.0.6

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.12

mozilla firefox 2.0.0.16

mozilla firefox 2.0.0.11

mozilla firefox 2.0.0.4

mozilla firefox 2.0.0.3

mozilla firefox 1.5.0.3

mozilla firefox 1.5.0.11

mozilla firefox 1.5.1

mozilla firefox 1.5.2

mozilla firefox 1.5.6

mozilla firefox 1.5.5

mozilla firefox 1.0.7

mozilla firefox 1.0.6

mozilla firefox 3.5.15

mozilla firefox 3.5.16

mozilla firefox 3.6.7

mozilla firefox 3.6.3

mozilla firefox 3.6.14

mozilla firefox 3.6.15

mozilla firefox 3.5.3

mozilla firefox 3.5.4

mozilla firefox 3.5

mozilla firefox 3.0.17

mozilla firefox 3.0.10

mozilla firefox 3.0.9

mozilla firefox 3.0.1

mozilla firefox 3.0

mozilla firefox 2.0.0.17

mozilla firefox 2.0.0.10

mozilla firefox 2.0.0.18

mozilla firefox 2.0.0.6

mozilla firefox 2.0.0.5

mozilla firefox 1.5.0.5

mozilla firefox 1.5.0.2

mozilla firefox 1.5.3

mozilla firefox 1.5.4

mozilla firefox 1.5.8

mozilla firefox 1.5.7

mozilla firefox 1.0.5

mozilla firefox 1.0.4

mozilla firefox 3.5.13

mozilla firefox 3.5.14

mozilla firefox 3.6.8

mozilla firefox 3.6.6

mozilla firefox 3.5.18

mozilla firefox 3.5.19

mozilla thunderbird 3.0.2

mozilla thunderbird 3.0.3

mozilla thunderbird 3.1.7

mozilla thunderbird 3.1.3

mozilla thunderbird 3.1.1

mozilla thunderbird 3.1

mozilla thunderbird 3.0.7

mozilla thunderbird 3.1.4

mozilla thunderbird 3.1.10

mozilla thunderbird 3.1.11

mozilla thunderbird 3.0

mozilla thunderbird 3.0.5

mozilla thunderbird 3.0.6

mozilla thunderbird 3.0.10

mozilla thunderbird 3.0.8

mozilla thunderbird 3.1.5

mozilla thunderbird 3.0.9

mozilla thunderbird 3.1.2

mozilla thunderbird 3.0.1

mozilla thunderbird 3.0.4

mozilla thunderbird 3.0.11

mozilla thunderbird 3.1.6

mozilla seamonkey 2.0.10

mozilla seamonkey 2.0.6

mozilla seamonkey 2.0.5

mozilla seamonkey 2.0

mozilla seamonkey 2.0.14

mozilla seamonkey 2.1

mozilla seamonkey 2.0.9

mozilla seamonkey 2.0.4

mozilla seamonkey 2.0.12

mozilla seamonkey 2.0.13

mozilla seamonkey 2.0.11

mozilla seamonkey 2.0.1

mozilla seamonkey 2.0.8

mozilla seamonkey 2.0.7

mozilla seamonkey 2.0.3

mozilla seamonkey 2.0.2

Vendor Advisories

Multiple vulnerabilities have been fixed in Thunderbird ...
Multiple vulnerabilities have been fixed in Firefox and Xulrunner ...
Several vulnerabilities have been discovered in Icedove, an unbranded version of the Thunderbird mail/news client CVE-2011-0084 regenrecht discovered that incorrect pointer handling in the SVG processing code could lead to the execution of arbitrary code CVE-2011-2378 regenrecht discovered that incorrect memory management in DOM proc ...
Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey: CVE-2011-0084 regenrecht discovered that incorrect pointer handling in the SVG processing code could lead to the execution of arbitrary code CVE-2011-2378 regenrecht discovered that incorrect memory management in DOM processing cou ...
Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox The included XULRunner library provides rendering services for several other applications included in Debian CVE-2011-0084 regenrecht discovered that incorrect pointer handling in the SVG processing code could lead to the execution of arbitrary code ...
Mozilla Foundation Security Advisory 2011-30 Security issues addressed in Firefox 3620 Announced August 16, 2011 Impact Critical Products Firefox Fixed in Firefox 3620 ...
Mozilla Foundation Security Advisory 2011-32 Security issues addressed in Thunderbird 3112 Announced August 16, 2011 Impact Critical Products Thunderbird Fixed in Thunderbird 3112 ...