VYPR
Unrated severityNVD Advisory· Published Aug 18, 2011· Updated Apr 29, 2026

CVE-2011-2378

CVE-2011-2378

Description

AppendChild in Firefox <3.6.20, Thunderbird <3.1.12, SeaMonkey 2.x mishandles DOM objects, leading to a dangling pointer and arbitrary code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

AppendChild in Firefox <3.6.20, Thunderbird <3.1.12, SeaMonkey 2.x mishandles DOM objects, leading to a dangling pointer and arbitrary code execution.

Vulnerability

The appendChild function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, SeaMonkey 2.x, and possibly other products does not properly handle DOM objects, which allows a dangling pointer to be dereferenced. This is a memory safety bug triggered by specific DOM manipulation sequences [1][2][3][4].

Exploitation

An attacker can trigger the vulnerability by convincing a victim to visit a specially crafted web page or open a malicious message. No authentication or special network position is required; the code path is reachable via standard DOM scripting. The attacker leverages a dangling pointer created by inconsistent DOM tree updates during appendChild operations [3][4].

Impact

Successful exploitation can lead to arbitrary code execution in the context of the affected application. The vulnerability is rated Critical, as it could allow full compromise of the user's system, including reading, modifying, or deleting files and installing malware [1][2][3].

Mitigation

Firefox was fixed in version 3.6.20, Thunderbird in 3.1.12, and SeaMonkey in version 2.3. Users should upgrade to these or later versions. Red Hat provided updated packages via RHSA-2011-1164 and RHSA-2011-1166 for their distributions [1][2][3].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

160
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 110 more
    • cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <=3.6.19
    • cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0:preview_release:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.15:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.16:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.17:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.18:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.19:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.20:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.15:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.16:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.17:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.15:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.16:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.17:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.18:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.19:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.15:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.16:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.17:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.18:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.9:*:*:*:*:*:*:*
    • (no CPE)range: <3.6.20
  • cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:*+ 25 more
    • cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:beta_1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:beta_2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.1:alpha1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.1:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.1:alpha3:*:*:*:*:*:*
    • (no CPE)
  • cpe:2.3:a:mozilla:thunderbird:3.0:*:*:*:*:*:*:*+ 22 more
    • cpe:2.3:a:mozilla:thunderbird:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.1.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.1.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.1.7:*:*:*:*:*:*:*
    • (no CPE)range: >=3.0, <3.1.12

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

11

News mentions

0

No linked articles in our index yet.