Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11077
http://www.zerodayinitiative.com/advisories/ZDI-06-051.html
http://www.vupen.com/english/advisories/2008/0083
http://www.vupen.com/english/advisories/2006/5068
http://www.us-cert.gov/cas/techalerts/TA06-354A.html
http://www.ubuntu.com/usn/usn-398-2
http://www.ubuntu.com/usn/usn-398-1
http://www.securityfocus.com/bid/21668
http://www.securityfocus.com/archive/1/455728/100/200/threaded
http://www.securityfocus.com/archive/1/455145/100/0/threaded
http://www.securityfocus.com/archive/1/454939/100/0/threaded
http://www.mozilla.org/security/announce/2006/mfsa2006-73.html
http://www.mandriva.com/security/advisories?name=MDKSA-2007:010
http://www.kb.cert.org/vuls/id/928956
http://www.gentoo.org/security/en/glsa/glsa-200701-04.xml
http://securitytracker.com/id?1017418
http://securitytracker.com/id?1017417
http://security.gentoo.org/glsa/glsa-200701-02.xml
http://secunia.com/advisories/23692
http://secunia.com/advisories/23672
http://secunia.com/advisories/23618
http://secunia.com/advisories/23614
http://secunia.com/advisories/23601
http://secunia.com/advisories/23589
http://secunia.com/advisories/23545
http://secunia.com/advisories/23514
http://secunia.com/advisories/23468
http://secunia.com/advisories/23440
http://secunia.com/advisories/23439
http://secunia.com/advisories/23433
http://secunia.com/advisories/23422
http://secunia.com/advisories/23282
http://rhn.redhat.com/errata/RHSA-2006-0760.html