Sploitus

CVE-2011-3654

1 known exploit for CVE-2011-3654

The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly handle links from SVG mpath elements to non-SVG elements, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

Affected products
Firefox, Thunderbird, Suse
Mozilla Firefox
≤ 7.0.1, 0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.6.1, 0.7, 0.7.1, 0.8, 0.9, 0.9.1, 0.9.2, 0.9.3, 0.10, 0.10.1, 1.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.4.1, 1.5, 1.5.0.1, 1.5.0.2, 1.5.0.3, 1.5.0.4, 1.5.0.5, 1.5.0.6, 1.5.0.7, 1.5.0.8, 1.5.0.9, 1.5.0.10, 1.5.0.11, 1.5.0.12
Fix
Available
CVSS 2.0
10.0 HIGH
EPSS
4.4% (90th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2011-11-09
CVE-2011-3654 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2011-3654

Proof-of-concept code and exploit modules indexed by Sploitus