Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9834
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7546
https://exchange.xforce.ibmcloud.com/vulnerabilities/57390
https://bugzilla.mozilla.org/show_bug.cgi?id=540100
https://bugzilla.mozilla.org/show_bug.cgi?id=375928
http://www.zerodayinitiative.com/advisories/ZDI-10-050
http://www.vupen.com/english/advisories/2010/0849
http://www.vupen.com/english/advisories/2010/0790
http://www.vupen.com/english/advisories/2010/0781
http://www.vupen.com/english/advisories/2010/0765
http://www.vupen.com/english/advisories/2010/0764
http://www.vupen.com/english/advisories/2010/0748
http://www.securityfocus.com/archive/1/510542/100/0/threaded
http://www.redhat.com/support/errata/RHSA-2010-0333.html
http://www.redhat.com/support/errata/RHSA-2010-0332.html
http://www.mozilla.org/security/announce/2010/mfsa2010-17.html
http://www.mandriva.com/security/advisories?name=MDVSA-2010:070
http://www.debian.org/security/2010/dsa-2027
http://ubuntu.com/usn/usn-921-1
http://securitytracker.com/id?1023782
http://securitytracker.com/id?1023780
http://secunia.com/advisories/39397
http://secunia.com/advisories/39308
http://secunia.com/advisories/39243
http://secunia.com/advisories/39242
http://secunia.com/advisories/39240
http://secunia.com/advisories/39204
http://secunia.com/advisories/39136
http://secunia.com/advisories/39117
http://secunia.com/advisories/38566
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038406.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038378.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038367.html