CVE-2011-0083: Use After Free
Use-after-free vulnerability in the nsSVGPathSegList::ReplaceItem function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0083?
CVE-2011-0083 is categorized as a critical vulnerability due to its potential to cause application crashes and possibly allow for remote code execution.
How do I fix CVE-2011-0083?
To fix CVE-2011-0083, update your Mozilla Firefox, Thunderbird, or SeaMonkey to the latest version, specifically versions after 3.6.18 for Firefox, 3.1.11 for Thunderbird, and 2.0.14 for SeaMonkey.
What applications are affected by CVE-2011-0083?
CVE-2011-0083 affects Mozilla Firefox prior to 3.6.18, Thunderbird prior to 3.1.11, and SeaMonkey through 2.0.14.
What type of vulnerability is CVE-2011-0083?
CVE-2011-0083 is a use-after-free vulnerability that can be exploited during the handling of SVG element lists.
Can CVE-2011-0083 lead to information leakage?
While CVE-2011-0083 primarily causes denial of service through application crashes, it may also potentially allow for further exploitation leading to information leakage.