Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a “dangling pointer.”
downloads.avaya.com/css/P8/documents/100134543
downloads.avaya.com/css/P8/documents/100144158
securityreason.com/securityalert/8310
www.debian.org/security/2011/dsa-2227
www.debian.org/security/2011/dsa-2228
www.debian.org/security/2011/dsa-2235
www.mandriva.com/security/advisories?name=MDVSA-2011:079
www.mozilla.org/security/announce/2011/mfsa2011-13.html
bugzilla.mozilla.org/show_bug.cgi?id=630919
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14020