CVE-2011-2363
published 2011-06-30CVE-2011-2363: Use-after-free vulnerability in the nsSVGPointList::AppendElement function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18…
PriorityP338critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.77%
92.2th percentile
Use-after-free vulnerability in the nsSVGPointList::AppendElement function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.
Affected
236 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.6.17 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2011-07-15·CVSS 10.0
CVE-2011-0083 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Multiple vulnerabilities were fixed in Thunderbird.
Multiple memory vulnerabilities were discovered in the browser rendering
engine. An attacker could use these to possibly execute arbitrary code with
the privileges of the user invoking Thunderbird. (CVE-2011-2364,
CVE-2011-2365, CVE-2011-2374, CVE-2011-2376)
Martin Barbella discovered that under certain conditions, viewing a XUL
document while JavaScript was disabled caused deleted memory to be
accessed. An attacker could potentially use this to crash Thunderbird or
execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2011-2373)
Jordi Chancel discovered a vulnerability on multipart/x-mixed-replace
images due to memory corruption. An attacker could potentially use
Ubuntu
Firefox regression
vendor_ubuntu·2011-06-29·CVSS 10.0
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: In rare instances, Firefox could have trouble accessing some websites.
USN-1149-1 fixed vulnerabilities in Firefox. Unfortunately, a regression
was introduced that prevented cookies from being stored properly when the
hostname was a single character. This update fixes the problem. We
apologize for the inconvenience.
Original advisory details:
Multiple memory vulnerabilities were discovered in the browser rendering
engine. An attacker could use these to possibly execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2011-2364, CVE-2011-2365,
CVE-2011-2374, CVE-2011-2376)
Martin Barbella discovered that under certain conditions, viewing a XUL
document while JavaScript was disabled caused deleted memory to be
accessed. An attacker
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2011-06-22·CVSS 10.0
CVE-2011-2364 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Multiple Vulnerabilities were fixed in Firefox and Xulrunner
Multiple memory vulnerabilities were discovered in the browser rendering
engine. An attacker could use these to possibly execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2011-2364, CVE-2011-2365,
CVE-2011-2374, CVE-2011-2376)
Martin Barbella discovered that under certain conditions, viewing a XUL
document while JavaScript was disabled caused deleted memory to be
accessed. An attacker could potentially use this to crash Firefox or
execute arbitrary code with the privileges of the user invoking Firefox.
(CVE-2011-2373)
Jordi Chancel discovered a vulnerability on multipart/x-mixed-replace
images due to memory corruption. An attacker could potentia
Red Hat
Mozilla Multiple dangling pointer vulnerabilities (MFSA 2011-23)
vendor_redhat·2011-06-21·CVSS 10.0
CVE-2011-2363 [CRITICAL] Mozilla Multiple dangling pointer vulnerabilities (MFSA 2011-23)
Mozilla Multiple dangling pointer vulnerabilities (MFSA 2011-23)
Use-after-free vulnerability in the nsSVGPointList::AppendElement function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.
GHSA
GHSA-xx6j-mphq-3862: Use-after-free vulnerability in the nsSVGPointList::AppendElement function in the implementation of SVG element lists in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-17
CVE-2011-2363 [HIGH] GHSA-xx6j-mphq-3862: Use-after-free vulnerability in the nsSVGPointList::AppendElement function in the implementation of SVG element lists in Mozilla Firefox before 3
Use-after-free vulnerability in the nsSVGPointList::AppendElement function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.
No detection rules found.
No public exploits indexed.
arXiv
Most Websites Don't Need to Vibrate: A Cost-Benefit Approach to Improving Browser Security
arxiv_fulltext·2017-09-05
Most Websites Don't Need to Vibrate: A Cost-Benefit Approach to Improving Browser Security
Most Websites Don't Need to Vibrate:
A Cost--Benefit Approach to Improving Browser Security
Peter Snyder
University Of Illinois at Chicago
[email protected]
Cynthia Taylor
University Of Illinois at Chicago
[email protected]
Chris Kanich
University Of Illinois at Chicago
[email protected]
JavaScript
Web API standard
Web API
Web API standards
Alexa 10k
Firefox 43.0.1
74
1679
40
60
96.74%
.03
1,554
41
953
175
39
188
13
https://github.com/snyderp/firefox-api-blocking-extension
URL Redacted for review.
URL Redacted for review.
20
23
lightgrayrgb.9,.9,.9
darkgrayrgb.4,.4,.4
purplergb0.65, 0.12, 0.82
JavaScript
keywords=break, case, catch, continue, debugger, default, delete, do, else, false, finally, for, function, if, in, instanceof, new, null, return, switch, this, thro
Bugzilla
CVE-2011-0083 CVE-2011-0085 CVE-2011-2363 Mozilla Multiple dangling pointer vulnerabilities (MFSA 2011-23)
bugzilla·2011-06-20·CVSS 10.0
CVE-2011-0083 [CRITICAL] CVE-2011-0083 CVE-2011-0085 CVE-2011-2363 Mozilla Multiple dangling pointer vulnerabilities (MFSA 2011-23)
CVE-2011-0083 CVE-2011-0085 CVE-2011-2363 Mozilla Multiple dangling pointer vulnerabilities (MFSA 2011-23)
Multiple dangling pointer vulnerabilities were reported by regenrecht via
TippingPoint's Zero Day Initiative.
Firefox 4 and newer products were not affected by these issues.
Discussion:
Public now via:
[1] http://www.mozilla.org/security/announce/2011/mfsa2011-23.html
---
Further flaws description (from [1]):
Security researcher regenrecht reported via TippingPoint's Zero Day Initiative
two instances of code which modifies SVG element lists failed to account for
changes made to the list by user-supplied callbacks before accessing list
elements. If a user-supplied callback deleted such an object, the element-
modifying code could wind up accessing deleted memory and potentially
http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00001.htmlhttp://secunia.com/advisories/45002http://support.avaya.com/css/P8/documents/100144854http://support.avaya.com/css/P8/documents/100145333http://www.debian.org/security/2011/dsa-2268http://www.debian.org/security/2011/dsa-2269http://www.debian.org/security/2011/dsa-2273http://www.mandriva.com/security/advisories?name=MDVSA-2011:111http://www.mozilla.org/security/announce/2011/mfsa2011-23.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0885.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0886.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0887.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0888.htmlhttp://www.ubuntu.com/usn/USN-1149-1https://bugzilla.mozilla.org/show_bug.cgi?id=648160https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14046http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00001.htmlhttp://secunia.com/advisories/45002http://support.avaya.com/css/P8/documents/100144854http://support.avaya.com/css/P8/documents/100145333http://www.debian.org/security/2011/dsa-2268http://www.debian.org/security/2011/dsa-2269http://www.debian.org/security/2011/dsa-2273http://www.mandriva.com/security/advisories?name=MDVSA-2011:111http://www.mozilla.org/security/announce/2011/mfsa2011-23.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0885.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0886.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0887.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0888.htmlhttp://www.ubuntu.com/usn/USN-1149-1https://bugzilla.mozilla.org/show_bug.cgi?id=648160https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14046
2011-06-30
Published