Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict the role of property changes in triggering XUL tree removal, which allows remote attackers to cause a denial of service (deleted memory access and application crash) or possibly execute arbitrary code by setting unspecified properties.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12001
https://exchange.xforce.ibmcloud.com/vulnerabilities/61653
https://bugzilla.mozilla.org/show_bug.cgi?id=576075
http://www.vupen.com/english/advisories/2011/0061
http://www.vupen.com/english/advisories/2010/2323
http://www.securityfocus.com/bid/43108
http://www.mozilla.org/security/announce/2010/mfsa2010-55.html
http://www.mandriva.com/security/advisories?name=MDVSA-2010:173
http://www.debian.org/security/2010/dsa-2106
http://support.avaya.com/css/P8/documents/100112690
http://support.avaya.com/css/P8/documents/100110210
http://secunia.com/advisories/42867
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00002.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-September/047282.html
http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox