Vulnerability record · CVE-2011-0073 · published 7 May 2011
CVE-2011-0073: Firefox and SeaMonkey nsTreeRange dangling pointer allows code execution
Mozilla · Firefox
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, mishandle nsTreeRange data structures, producing a dangling pointer. A remote attacker can trigger this with unspecified vectors and execute arbitrary code in the context of the browser.
Description
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 2.0 score is 10.0 and EPSS is very high, but the flaw affects only long-outdated browser versions and no KEV or public exploit tag is present.
What it is
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, mishandle nsTreeRange data structures, producing a dangling pointer. A remote attacker can trigger this with unspecified vectors and execute arbitrary code in the context of the browser.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the affected browser process. This can lead to full compromise of the user's system.
Attack surface
The vulnerability is reachable over the network (AV:N) with no authentication (Au:N) and low attack complexity (AC:L), consistent with a malicious web page or content. No user interaction detail is given beyond the remote vector, but typical browser exploitation requires the victim to load attacker-controlled content.
Exploitation
CVE-2011-0073 is not listed in CISA KEV and no ransomware group usage is documented. EPSS is high (0.70213, 99.3rd percentile), but the record contains no reference tags indicating a public exploit.
What to do
- Upgrade Firefox to 3.5.19 or later, or 3.6.17 or later, and SeaMonkey to 2.0.14 or later.
- Apply the vendor advisory MFSA 2011-13 and any distribution backports (Debian DSA-2227/2228/2235, Mandriva MDVSA-2011:079).
- If legacy browsers cannot be patched, restrict browsing to trusted sites and isolate the browser from sensitive data.
- Retire or replace end-of-life Firefox and SeaMonkey versions that cannot receive the fix.
Detection
- Monitor for crashes in Firefox or SeaMonkey involving nsTreeRange or tree-related code paths.
- Hunt for unexpected child processes spawned by the browser, which can indicate successful code execution.
- Review proxy or IDS logs for known exploit delivery patterns against Firefox 3.5.x/3.6.x and SeaMonkey 2.0.x.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-0073 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-0073), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.