CVE-2011-0084
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x be
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5.
Thunderbird 3.x before 3.1.12 and other versions before 6.
SeaMonkey 2.x before 2.3.
and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer.".
HIGH · CVSS 10
EPSS 0.05475
Schedule remediation
- EPSS percentile: top 10% of all CVEs by exploitation likelihood
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0