7.5
CVE-2011-3671
- EPSS 1.86%
- Veröffentlicht 18.06.2012 19:55:01
- Zuletzt bearbeitet 16.06.2026 23:33:44
- Erkennungen
Use-after-free vulnerability in the nsHTMLSelectElement function in nsHTMLSelectElement.cpp in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allows remote attackers to execute arbitrary code via vectors involving removal of the parent node of an element.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Thunderbird Version 5.0
Mozilla ≫ Thunderbird Version 6.0
Mozilla ≫ Thunderbird Version 6.0.1
Mozilla ≫ Thunderbird Version 6.0.2
Mozilla ≫ Thunderbird Version 7.0
Mozilla ≫ Thunderbird Version 7.0.1
Mozilla ≫ Thunderbird Version 8.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.86% | 0.77 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://www.mozilla.org/security/announce/2012/mfsa2012-41.html
https://bugzilla.mozilla.org/show_bug.cgi?id=739343