CVE-2011-3658
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 70%
from disclosure to weapon140 days
Published on NVDDec 21
1st PoC+140d
metasploitDec 6
exploitation probability
70%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via vectors involving removal of SVG elements.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/18847unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00009.htmlhttp://lists.opensuse.org/opensuse-updates/2012-03/msg00042.htmlhttp://osvdb.org/77953https://bugzilla.mozilla.org/show_bug.cgi?id=708186http://secunia.com/advisories/47302http://secunia.com/advisories/47334http://secunia.com/advisories/48495http://secunia.com/advisories/48553http://secunia.com/advisories/48823http://secunia.com/advisories/49055https://exchange.xforce.ibmcloud.com/vulnerabilities/71910