Use-after-free vulnerability in the nsSVGPathSegList::ReplaceItem function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade firefoxUpgrade seamonkeyUpgrade seamonkey-dom-inspectorUpgrade seamonkey-js-debuggerUpgrade thunderbirdUpgrade seamonkey-mailUpgrade seamonkey-develUpgrade seamonkey-chatUpgrade xulrunner-develUpgrade xulrunner | Dec 1, 2016 | Jun 30, 2011 |
| Gentoo Linux | — | Upgrade www-client/seamonkey.Upgrade www-client/seamonkey-bin.Upgrade www-client/icecat.Upgrade dev-libs/nss.Upgrade net-libs/xulrunner.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/firefox.Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox-bin.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/thunderbird. | Oct 30, 2017 | Jun 30, 2011 |
| Mfsa2011 23 | — | Upgrade to Mozilla Firefox version 3.6.18 | Jun 14, 2012 | Jun 30, 2011 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 3.1.11 | Feb 22, 2012 | Jun 30, 2011 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade xulrunnerUpgrade xulrunner-develUpgrade firefox | Oct 16, 2024 | Jun 30, 2011 |
| Suse | — | Upgrade mozilla-xulrunner192-translations-common-32bitUpgrade mozilla-xulrunner192-gnomeUpgrade mozilla-xulrunner192-buildsymbolsUpgrade MozillaThunderbird-buildsymbolsUpgrade mozilla-xulrunner192-translations-otherUpgrade mozillafirefox-translations-commonUpgrade mozilla-xulrunner192Upgrade mozilla-xulrunner192-translations-other-32bitUpgrade mozilla-xulrunner192-gnome-32bitUpgrade mozillafirefox-develUpgrade mozilla-xulrunner192-develUpgrade sap-aio-releaseUpgrade mozillathunderbirdUpgrade enigmailUpgrade mozilla-xulrunner192-32bitUpgrade MozillaFirefox-translationsUpgrade mozilla-xulrunner192-translationsUpgrade MozillaFirefox-branding-openSUSEUpgrade mozillathunderbird-translations-otherUpgrade mozilla-xulrunner192-translations-32bitUpgrade MozillaThunderbird-develUpgrade mozilla-js192-32bitUpgrade mozilla-js192Upgrade mozillafirefox-buildsymbolsUpgrade mozillafirefoxUpgrade mozillafirefox-translations-otherUpgrade mozilla-xulrunner192-translations-commonUpgrade mozillafirefox-branding-upstreamUpgrade mozillathunderbird-translations-common | Feb 17, 2015 | Jun 30, 2011 |
| Ubuntu | — | Upgrade xulrunner-1.9.2Upgrade thunderbirdUpgrade firefox | Nov 8, 2024 | Jun 30, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub