peter bassill · operator
$ cve CVE-2011-3659 JSON

CVE-2011-3659 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 36.8% (pctl 98)

Patch early

A public exploit exists.

Description

Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS36.82% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-416
On CISA KEVno
Public exploityes
Published2012-02-01
Last modified2026-06-16

Affected (7)

VendorProduct
mozillafirefox
mozillaseamonkey
mozillathunderbird
opensuseopensuse
suselinux enterprise desktop
suselinux enterprise server
suselinux enterprise software development kit

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD