CVE-2011-3659

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes.

References

http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00003.html

http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00007.html

http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00011.html

http://www.mandriva.com/security/advisories?name=MDVSA-2012:013

http://www.mozilla.org/security/announce/2012/mfsa2012-04.html

https://bugzilla.mozilla.org/show_bug.cgi?id=708198

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14697

Details

Source: MITRE

Published: 2012-02-01

Updated: 2020-08-28

Type: CWE-416

Risk Information

CVSS v2

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

Tenable Plugins

View all (45 total)

IDNameProductFamilySeverity
80788Oracle Solaris Third-Party Patch Update : thunderbird (multiple_vulnerabilities_in_thunderbird6)NessusSolaris Local Security Checks
critical
76026openSUSE Security Update : seamonkey (seamonkey-5768)NessusSuSE Local Security Checks
critical
75969openSUSE Security Update : MozillaThunderbird (MozillaThunderbird-5751)NessusSuSE Local Security Checks
critical
75961openSUSE Security Update : mozilla-js192 (mozilla-js192-5749)NessusSuSE Local Security Checks
critical
75951openSUSE Security Update : MozillaFirefox (MozillaFirefox-5750)NessusSuSE Local Security Checks
critical
74833openSUSE Security Update : MozillaFirefox / MozillaThunderbird / chmsee / etc (openSUSE-2012-83)NessusSuSE Local Security Checks
critical
68444Oracle Linux 6 : thunderbird (ELSA-2012-0080)NessusOracle Linux Local Security Checks
high
68443Oracle Linux 4 / 5 / 6 : firefox (ELSA-2012-0079)NessusOracle Linux Local Security Checks
critical
63402GLSA-201301-01 : Mozilla Products: Multiple vulnerabilities (BEAST)NessusGentoo Local Security Checks
critical
61231Scientific Linux Security Update : thunderbird on SL6.x i386/x86_64 (20120131)NessusScientific Linux Local Security Checks
high
61230Scientific Linux Security Update : firefox on SL4.x, SL5.x, SL6.x i386/x86_64 (20120131)NessusScientific Linux Local Security Checks
critical
58037Ubuntu 11.10 : thunderbird vulnerabilities (USN-1369-1)NessusUbuntu Local Security Checks
critical
57886SuSE 11.1 Security Update : Mozilla XULrunner (SAT Patch Number 5764)NessusSuSE Local Security Checks
critical
57874Ubuntu 10.04 LTS / 10.10 : xulrunner-1.9.2 vulnerabilities (USN-1353-1)NessusUbuntu Local Security Checks
critical
57873Ubuntu 10.04 LTS / 10.10 / 11.04 : thunderbird vulnerabilities (USN-1350-1)NessusUbuntu Local Security Checks
critical
57858SuSE 10 Security Update : Mozilla Firefox (ZYPP Patch Number 7949)NessusSuSE Local Security Checks
critical
801371Mozilla Thunderbird 3.1.x Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801334Mozilla SeaMonkey 2.x < 2.7.0 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801296Mozilla Firefox 9.0 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801268Mozilla Firefox 3.6.x < 3.6.26 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801248Mozilla Thunderbird 9.0 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
6310SeaMonkey 2.x < 2.7.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
6309Mozilla Thunderbird 3.1.x < 3.1.18 Multiple VulnerabilitiesNessus Network MonitorSMTP Clients
high
6308Mozilla Thunderbird < 10.0 Multiple VulnerabilitiesNessus Network MonitorSMTP Clients
high
6307Mozilla Firefox 3.6.x < 3.6.26 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
6306Mozilla Firefox < 10.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
57846Ubuntu 10.04 LTS / 10.10 : ubufox and webfav update (USN-1355-3)NessusUbuntu Local Security Checks
critical
57845Ubuntu 10.04 LTS / 10.10 / 11.04 / 11.10 : mozvoikko update (USN-1355-2)NessusUbuntu Local Security Checks
critical
57844Ubuntu 10.04 LTS / 10.10 / 11.04 / 11.10 : firefox vulnerabilities (USN-1355-1)NessusUbuntu Local Security Checks
critical
57838SuSE 11.1 Security Update : MozillaFirefox (SAT Patch Number 5754)NessusSuSE Local Security Checks
critical
57833Mandriva Linux Security Advisory : mozilla (MDVSA-2012:013)NessusMandriva Local Security Checks
critical
57785FreeBSD : mozilla -- multiple vulnerabilities (0a9e2b72-4cb7-11e1-9146-14dae9ebcf89)NessusFreeBSD Local Security Checks
critical
57778CentOS 6 : thunderbird (CESA-2012:0080)NessusCentOS Local Security Checks
high
57777CentOS 4 / 5 / 6 : firefox (CESA-2012:0079)NessusCentOS Local Security Checks
critical
57776Thunderbird 3.1 < 3.1.18 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
57775Thunderbird 9.x Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
57774Firefox 3.6 < 3.6.26 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
57773Firefox < 10.0 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
57772SeaMonkey < 2.7.0 Multiple VulnerabilitiesNessusWindows
high
57771Mozilla Thunderbird 3.1.x < 3.1.18 Multiple VulnerabilitiesNessusWindows
high
57770Mozilla Thunderbird < 10.0 Multiple VulnerabilitiesNessusWindows
high
57769Firefox 3.6.x < 3.6.26 Multiple VulnerabilitiesNessusWindows
high
57768Firefox < 10.0 Multiple VulnerabilitiesNessusWindows
high
57761RHEL 6 : thunderbird (RHSA-2012:0080)NessusRed Hat Local Security Checks
high
57760RHEL 4 / 5 / 6 : firefox (RHSA-2012:0079)NessusRed Hat Local Security Checks
critical