CVE-2011-3671: Use After Free
Use-after-free vulnerability in the nsHTMLSelectElement function in nsHTMLSelectElement.cpp in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allows remote attackers to execute arbitrary code via vectors involving removal of the parent node of an element.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3671?
CVE-2011-3671 is classified as a critical severity vulnerability allowing arbitrary code execution.
How do I fix CVE-2011-3671?
To fix CVE-2011-3671, users should upgrade to the latest versions of Mozilla Firefox, Thunderbird, or SeaMonkey that have patched this vulnerability.
What versions are affected by CVE-2011-3671?
CVE-2011-3671 affects Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey versions before 2.6.
Can CVE-2011-3671 be exploited remotely?
Yes, CVE-2011-3671 can be exploited remotely by attackers through vectors that involve manipulation of DOM elements.
Is there a workaround for CVE-2011-3671 if I can't upgrade?
There are no reliable workarounds for CVE-2011-3671, so upgrading to a fixed version is essential for protection.