Vulnerability record · CVE-2011-0065 · published 7 May 2011
CVE-2011-0065: Mozilla Firefox and SeaMonkey use-after-free in OBJECT mChannel
Mozilla · Firefox
A use-after-free flaw exists in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, related to OBJECT's mChannel. A remote attacker can trigger the freed memory condition and potentially execute arbitrary code in the context of the browser. The record does not include a detailed technical description beyond the mChannel reference.
Description
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mChannel.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 2.0 score of 10 indicates maximum severity, and the high EPSS percentile suggests likely exploitation, but the lack of KEV listing and specific exploit details keeps it from critical.
What it is
A use-after-free flaw exists in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, related to OBJECT's mChannel. A remote attacker can trigger the freed memory condition and potentially execute arbitrary code in the context of the browser. The record does not include a detailed technical description beyond the mChannel reference.
Impact
Successful exploitation can lead to arbitrary code execution with the privileges of the affected browser process. This could allow an attacker to install malware, steal data, or take control of the user's system.
Attack surface
The vulnerability is reachable remotely over the network with no authentication required, per the CVSS vector AV:N/AC:L/Au:N. User interaction is not explicitly stated in the record, but typical browser exploitation requires the victim to visit a malicious page or interact with crafted content.
Exploitation
The CVE is not listed in CISA KEV, and no reference tags indicate public exploit code or active exploitation. EPSS probability is 0.73835 (99.45th percentile), suggesting a high likelihood of exploitation activity in the wild, but this is a statistical estimate only.
What to do
- Upgrade to Firefox 3.5.19 or later, Firefox 3.6.17 or later, or SeaMonkey 2.0.14 or later as applicable.
- Apply vendor patches or distribution updates (e.g., Debian DSA-2227, DSA-2228, DSA-2235, Mandriva MDVSA-2011:079) for affected packages.
- If immediate patching is not possible, consider disabling or restricting JavaScript and plugin content in the browser, though this may not fully mitigate the flaw.
- Monitor vendor advisories (MFSA 2011-13) for any updated guidance or workarounds.
Detection
- Monitor for crashes or abnormal termination of Firefox or SeaMonkey processes, which may indicate attempted exploitation of use-after-free conditions.
- Use endpoint detection to look for suspicious child processes spawned by browser processes, a common post-exploitation behavior.
- Review network logs for known malicious domains or exploit kit traffic, though no specific indicators are provided in the record.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-0065 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-0065), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.