Vulnerability record · CVE-2011-3658 · published 21 December 2011
CVE-2011-3658: Mozilla Firefox SVG DOMAttrModified memory corruption flaw
Mozilla · Firefox
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 mishandles interaction with DOMAttrModified event handlers when SVG elements are removed. This leads to an out-of-bounds memory access that can crash the application or potentially allow other unspecified impact.
Description
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via vectors involving removal of SVG elements.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityNetwork-reachable, no authentication or interaction required, high CVSS 7.5, and very high EPSS despite no KEV listing.
What it is
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 mishandles interaction with DOMAttrModified event handlers when SVG elements are removed. This leads to an out-of-bounds memory access that can crash the application or potentially allow other unspecified impact.
Impact
A remote attacker can cause a denial of service through browser or mail client crashes, and the out-of-bounds memory access may permit further exploitation beyond a crash, though the record does not specify code execution.
Attack surface
Reachable over the network with no authentication and no user interaction beyond loading attacker-controlled content that triggers SVG element removal alongside DOMAttrModified handlers, per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit code, but EPSS is 0.69628 (99.33rd percentile), indicating a high modeled likelihood of exploitation activity.
What to do
- Upgrade Firefox, Thunderbird, and SeaMonkey to versions containing the fix referenced in Mozilla advisory mfsa2011-55.
- Apply vendor updates from the listed Linux distribution advisories (openSUSE, Ubuntu, Mandriva) for packaged builds.
- Disable or restrict SVG rendering in high-risk browsing or mail contexts where feasible.
- Enforce script and content controls so untrusted pages cannot freely manipulate SVG DOM events.
Detection
- Monitor for repeated browser or Thunderbird crashes tied to SVG-heavy pages or mail content.
- Hunt for crash reports referencing out-of-bounds access in SVG or DOMAttrModified handling paths.
- Review proxy or web logs for delivery of SVG content from untrusted or newly seen sources to vulnerable clients.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-3658 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-3658), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.