CVE-2011-2997: Mozilla Firefox

High severity, CVSS 10.0. EPSS: 5.5% chance of exploitation in the next 30 days.

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

Affected products

  • Mozilla Firefox: version 6.0 only
  • Mozilla Seamonkey: up to and including 2.3.3; version 1.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; …
  • Mozilla Thunderbird: up to and including 6.0.2; version 0.1 only; version 0.2 only; version 0.3 only; version 0.4 only; version 0.5 only; …

Published 2011-09-29. Last modified 2026-06-16.