CVE-2011-0073 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 70.2% (pctl 99)
Patch early
A public exploit exists.
Description
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 70.21% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-05-07 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | seamonkey |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mozilla Firefox - 'nsTreeRange' Dangling Pointer (Metasploit) (1) | 2011-07-10 |
| exploit-db | Mozilla Firefox - 'nsTreeRange' Dangling Pointer (2) | 2011-06-20 |
References
- http://downloads.avaya.com/css/P8/documents/100134543
- http://downloads.avaya.com/css/P8/documents/100144158
- http://securityreason.com/securityalert/8310
- http://www.debian.org/security/2011/dsa-2227
- http://www.debian.org/security/2011/dsa-2228
- http://www.debian.org/security/2011/dsa-2235
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:079
- http://www.mozilla.org/security/announce/2011/mfsa2011-13.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=630919
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14020
- http://downloads.avaya.com/css/P8/documents/100134543
- http://downloads.avaya.com/css/P8/documents/100144158
- http://securityreason.com/securityalert/8310
- http://www.debian.org/security/2011/dsa-2227
- http://www.debian.org/security/2011/dsa-2228
- http://www.debian.org/security/2011/dsa-2235
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:079
- http://www.mozilla.org/security/announce/2011/mfsa2011-13.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=630919
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14020
→ the Explorer · watch your stack · NVD