CVE-2011-0066Use After Free in Mozilla Firefox

Severity
10.0CRITICALNVD
EPSS
5.6%
top 9.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 7
Latest updateMay 17

Description

Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mObserverList.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDmozilla/firefox3.5.18+102
NVDmozilla/seamonkey2.0.13+46

🔴Vulnerability Details

2
GHSA
GHSA-7c8x-pggq-qrgr: Use-after-free vulnerability in Mozilla Firefox before 32022-05-17
CVEList
CVE-2011-0066: Use-after-free vulnerability in Mozilla Firefox before 32011-05-07

📋Vendor Advisories

6
Ubuntu
Thunderbird regression2011-06-06
Ubuntu
Thunderbird vulnerabilities2011-05-05
Ubuntu
Thunderbird vulnerabilities2011-05-05
Ubuntu
Xulrunner vulnerabilities2011-04-30
Ubuntu
Firefox and Xulrunner vulnerabilities2011-04-29

💬Community

1
Bugzilla
CVE-2011-0066 Mozilla mObserverList use after free (MFSA 2011-13)2011-04-28
CVE-2011-0066 — Use After Free in Mozilla Firefox | cvebase