CVE-2011-0085: Mozilla Multiple dangling pointer vulnerabilities (MFSA 2011-23)

Severity: Critical

CVSS Score: 10

Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via a crafted XUL document that dequeues the current command updater.