CVE-2011-2378
published 2011-08-18CVE-2011-2378: The appendChild function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, SeaMonkey 2.x, and possibly other products does not properly handle…
PriorityP347critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.56%
92.0th percentile
The appendChild function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, SeaMonkey 2.x, and possibly other products does not properly handle DOM objects, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to dereferencing of a "dangling pointer."
Affected
145 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.6.19 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2011-08-26·CVSS 10.0
CVE-2011-0084 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Multiple vulnerabilities have been fixed in Thunderbird.
Gary Kwong, Igor Bukanov, and Bob Clary discovered multiple memory
vulnerabilities in the Gecko rendering engine. An attacker could use
these to possibly execute arbitrary code with the privileges of the user
invoking Thunderbird. (CVE-2011-2982)
It was discovered that a vulnerability in event management code could
permit JavaScript to be run in the wrong context. This could potentially
allow a malicious website to run code as another website or with escalated
privileges in a chrome-privileged context. (CVE-2011-2981)
It was discovered that an SVG text manipulation routine contained a
dangling pointer vulnerability. An attacker could potentially use this to
crash Thunderbird or execute
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2011-08-19·CVSS 10.0
CVE-2011-2982 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Multiple vulnerabilities have been fixed in Firefox and Xulrunner.
Gary Kwong, Igor Bukanov, and Bob Clary discovered multiple memory
vulnerabilities in the browser rendering engine. An attacker could use
these to possibly execute arbitrary code with the privileges of the user
invoking Firefox. (CVE-2011-2982)
It was discovered that a vulnerability in event management code could
permit JavaScript to be run in the wrong context. This could potentially
allow a malicious website to run code as another website or with escalated
privileges within the browser. (CVE-2011-2981)
It was discovered that an SVG text manipulation routine contained a
dangling pointer vulnerability. An attacker could potentially use this to
crash Firefox or execut
Red Hat
Mozilla: Dangling pointer vulnerability in appendChild
vendor_redhat·2011-08-16·CVSS 10.0
CVE-2011-2378 [CRITICAL] Mozilla: Dangling pointer vulnerability in appendChild
Mozilla: Dangling pointer vulnerability in appendChild
The appendChild function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, SeaMonkey 2.x, and possibly other products does not properly handle DOM objects, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to dereferencing of a "dangling pointer."
Package: firefox (Red Hat Enterprise Linux Extended Update Support 5.7) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 6.1) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update Support 6.1) - Affected
GHSA
GHSA-q8vw-h86h-vfj9: The appendChild function in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-17
CVE-2011-2378 [HIGH] CWE-94 GHSA-q8vw-h86h-vfj9: The appendChild function in Mozilla Firefox before 3
The appendChild function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, SeaMonkey 2.x, and possibly other products does not properly handle DOM objects, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to dereferencing of a "dangling pointer."
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-08/msg00027.htmlhttp://www.debian.org/security/2011/dsa-2295http://www.debian.org/security/2011/dsa-2296http://www.debian.org/security/2011/dsa-2297http://www.mandriva.com/security/advisories?name=MDVSA-2011:127http://www.mozilla.org/security/announce/2011/mfsa2011-30.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1164.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1166.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=648065https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14163http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-08/msg00027.htmlhttp://www.debian.org/security/2011/dsa-2295http://www.debian.org/security/2011/dsa-2296http://www.debian.org/security/2011/dsa-2297http://www.mandriva.com/security/advisories?name=MDVSA-2011:127http://www.mozilla.org/security/announce/2011/mfsa2011-30.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1164.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1166.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=648065https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14163
2011-08-18
Published