Use-after-free vulnerability in the nsHTMLSelectElement function in nsHTMLSelectElement.cpp in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allows remote attackers to execute arbitrary code via vectors involving removal of the parent node of an element.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mfsa2012 41 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 9.0 | Jun 19, 2012 | Jun 18, 2012 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.6.0 | Jun 19, 2012 | Jun 18, 2012 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 9.0Upgrade to the latest version of Mozilla Thunderbird | Jun 19, 2012 | Jun 18, 2012 |
| Ubuntu | — | Upgrade thunderbirdUpgrade firefox | Nov 19, 2024 | Jun 18, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub