Description
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via vectors involving removal of SVG elements.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-1306-1 | Firefox vulnerabilities |
Ubuntu USN |
USN-1343-1 | Thunderbird vulnerabilities |
Ubuntu USN |
USN-1401-1 | Xulrunner vulnerabilities |
Ubuntu USN |
USN-1401-2 | Thunderbird vulnerabilities |
References
History
Wed, 28 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Thu, 22 May 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T23:46:01.401Z
Reserved: 2011-09-23T00:00:00.000Z
Link: CVE-2011-3658
No data.
Status : Deferred
Published: 2011-12-21T04:02:00.897
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-3658
OpenCVE Enrichment
No data.
Weaknesses
Ubuntu USN