First published: Thu Aug 18 2011(Updated: )
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <=3.6.19 | |
Firefox | =1.0 | |
Firefox | =1.0-preview_release | |
Firefox | =1.0.1 | |
Firefox | =1.0.2 | |
Firefox | =1.0.3 | |
Firefox | =1.0.4 | |
Firefox | =1.0.5 | |
Firefox | =1.0.6 | |
Firefox | =1.0.7 | |
Firefox | =1.0.8 | |
Firefox | =1.5 | |
Firefox | =1.5-beta1 | |
Firefox | =1.5-beta2 | |
Firefox | =1.5.0.1 | |
Firefox | =1.5.0.2 | |
Firefox | =1.5.0.3 | |
Firefox | =1.5.0.4 | |
Firefox | =1.5.0.5 | |
Firefox | =1.5.0.6 | |
Firefox | =1.5.0.7 | |
Firefox | =1.5.0.8 | |
Firefox | =1.5.0.9 | |
Firefox | =1.5.0.10 | |
Firefox | =1.5.0.11 | |
Firefox | =1.5.0.12 | |
Firefox | =1.5.1 | |
Firefox | =1.5.2 | |
Firefox | =1.5.3 | |
Firefox | =1.5.4 | |
Firefox | =1.5.5 | |
Firefox | =1.5.6 | |
Firefox | =1.5.7 | |
Firefox | =1.5.8 | |
Firefox | =2.0 | |
Firefox | =2.0.0.1 | |
Firefox | =2.0.0.2 | |
Firefox | =2.0.0.3 | |
Firefox | =2.0.0.4 | |
Firefox | =2.0.0.5 | |
Firefox | =2.0.0.6 | |
Firefox | =2.0.0.7 | |
Firefox | =2.0.0.8 | |
Firefox | =2.0.0.9 | |
Firefox | =2.0.0.10 | |
Firefox | =2.0.0.11 | |
Firefox | =2.0.0.12 | |
Firefox | =2.0.0.13 | |
Firefox | =2.0.0.14 | |
Firefox | =2.0.0.15 | |
Firefox | =2.0.0.16 | |
Firefox | =2.0.0.17 | |
Firefox | =2.0.0.18 | |
Firefox | =2.0.0.19 | |
Firefox | =2.0.0.20 | |
Firefox | =3.0 | |
Firefox | =3.0.1 | |
Firefox | =3.0.2 | |
Firefox | =3.0.3 | |
Firefox | =3.0.4 | |
Firefox | =3.0.5 | |
Firefox | =3.0.6 | |
Firefox | =3.0.7 | |
Firefox | =3.0.8 | |
Firefox | =3.0.9 | |
Firefox | =3.0.10 | |
Firefox | =3.0.11 | |
Firefox | =3.0.12 | |
Firefox | =3.0.13 | |
Firefox | =3.0.14 | |
Firefox | =3.0.15 | |
Firefox | =3.0.16 | |
Firefox | =3.0.17 | |
Firefox | =3.5 | |
Firefox | =3.5.1 | |
Firefox | =3.5.2 | |
Firefox | =3.5.3 | |
Firefox | =3.5.4 | |
Firefox | =3.5.5 | |
Firefox | =3.5.6 | |
Firefox | =3.5.7 | |
Firefox | =3.5.8 | |
Firefox | =3.5.9 | |
Firefox | =3.5.10 | |
Firefox | =3.5.11 | |
Firefox | =3.5.12 | |
Firefox | =3.5.13 | |
Firefox | =3.5.14 | |
Firefox | =3.5.15 | |
Firefox | =3.5.16 | |
Firefox | =3.5.17 | |
Firefox | =3.5.18 | |
Firefox | =3.5.19 | |
Firefox | =3.6 | |
Firefox | =3.6.2 | |
Firefox | =3.6.3 | |
Firefox | =3.6.4 | |
Firefox | =3.6.6 | |
Firefox | =3.6.7 | |
Firefox | =3.6.8 | |
Firefox | =3.6.9 | |
Firefox | =3.6.10 | |
Firefox | =3.6.11 | |
Firefox | =3.6.12 | |
Firefox | =3.6.13 | |
Firefox | =3.6.14 | |
Firefox | =3.6.15 | |
Firefox | =3.6.16 | |
Firefox | =3.6.17 | |
Firefox | =3.6.18 | |
Firefox | =4.0 | |
Firefox | =4.0-beta1 | |
Firefox | =4.0-beta10 | |
Firefox | =4.0-beta11 | |
Firefox | =4.0-beta12 | |
Firefox | =4.0-beta2 | |
Firefox | =4.0-beta3 | |
Firefox | =4.0-beta4 | |
Firefox | =4.0-beta5 | |
Firefox | =4.0-beta6 | |
Firefox | =4.0-beta7 | |
Firefox | =4.0-beta8 | |
Firefox | =4.0-beta9 | |
Firefox | =4.0.1 | |
Firefox | =5.0 | |
Mozilla SeaMonkey | =2.0 | |
Mozilla SeaMonkey | =2.0-alpha_1 | |
Mozilla SeaMonkey | =2.0-alpha_2 | |
Mozilla SeaMonkey | =2.0-alpha_3 | |
Mozilla SeaMonkey | =2.0-beta_1 | |
Mozilla SeaMonkey | =2.0-beta_2 | |
Mozilla SeaMonkey | =2.0-rc1 | |
Mozilla SeaMonkey | =2.0-rc2 | |
Mozilla SeaMonkey | =2.0.1 | |
Mozilla SeaMonkey | =2.0.2 | |
Mozilla SeaMonkey | =2.0.3 | |
Mozilla SeaMonkey | =2.0.4 | |
Mozilla SeaMonkey | =2.0.5 | |
Mozilla SeaMonkey | =2.0.6 | |
Mozilla SeaMonkey | =2.0.7 | |
Mozilla SeaMonkey | =2.0.8 | |
Mozilla SeaMonkey | =2.0.9 | |
Mozilla SeaMonkey | =2.0.10 | |
Mozilla SeaMonkey | =2.0.11 | |
Mozilla SeaMonkey | =2.0.12 | |
Mozilla SeaMonkey | =2.0.13 | |
Mozilla SeaMonkey | =2.0.14 | |
Mozilla SeaMonkey | =2.1-alpha1 | |
Mozilla SeaMonkey | =2.1-alpha2 | |
Mozilla SeaMonkey | =2.1-alpha3 | |
Thunderbird | =3.0 | |
Thunderbird | =3.0.1 | |
Thunderbird | =3.0.2 | |
Thunderbird | =3.0.3 | |
Thunderbird | =3.0.4 | |
Thunderbird | =3.0.5 | |
Thunderbird | =3.0.6 | |
Thunderbird | =3.0.7 | |
Thunderbird | =3.0.8 | |
Thunderbird | =3.0.9 | |
Thunderbird | =3.0.10 | |
Thunderbird | =3.0.11 | |
Thunderbird | =3.1 | |
Thunderbird | =3.1.1 | |
Thunderbird | =3.1.2 | |
Thunderbird | =3.1.3 | |
Thunderbird | =3.1.4 | |
Thunderbird | =3.1.5 | |
Thunderbird | =3.1.6 | |
Thunderbird | =3.1.7 | |
Thunderbird | =3.1.8 | |
Thunderbird | =3.1.9 | |
Thunderbird | =3.1.10 | |
Thunderbird | =3.1.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0084 is classified as a critical vulnerability that may allow remote attackers to execute arbitrary code.
CVE-2011-0084 affects Mozilla Firefox versions prior to 3.6.20, Thunderbird versions before 3.1.12, and SeaMonkey versions before 2.3.
To fix CVE-2011-0084, users should upgrade to a fixed version of the affected software, such as Firefox 3.6.20 or later.
The potential impact of CVE-2011-0084 includes remote code execution, which could compromise the integrity and confidentiality of affected systems.
There are no specific workarounds for CVE-2011-0084; it is recommended to update to the latest software version to mitigate the risk.