CVE-2011-0084: Code Injection
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0084?
CVE-2011-0084 is classified as a critical vulnerability that may allow remote attackers to execute arbitrary code.
Which software versions are affected by CVE-2011-0084?
CVE-2011-0084 affects Mozilla Firefox versions prior to 3.6.20, Thunderbird versions before 3.1.12, and SeaMonkey versions before 2.3.
How do I fix CVE-2011-0084?
To fix CVE-2011-0084, users should upgrade to a fixed version of the affected software, such as Firefox 3.6.20 or later.
What are the potential impacts of CVE-2011-0084?
The potential impact of CVE-2011-0084 includes remote code execution, which could compromise the integrity and confidentiality of affected systems.
Is there a workaround for CVE-2011-0084 until a patch can be applied?
There are no specific workarounds for CVE-2011-0084; it is recommended to update to the latest software version to mitigate the risk.