PT-2010-1997 · Mozilla · Firefox+1

Wushi

·

Publicado

2010-06-23

·

Atualizado

2017-09-19

·

CVE-2010-0183

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 3.5.x through 3.5.9 SeaMonkey versions prior to 2.0.5
Description A use-after-free issue exists in the nsCycleCollector::MarkRoots function, related to an improper frame construction process for menus. This allows remote attackers to execute arbitrary code via a crafted HTML document.
Recommendations For Mozilla Firefox versions 3.5.x through 3.5.9, update to version 3.5.10 or later. For SeaMonkey versions prior to 2.0.5, update to version 2.0.5 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-0183
DSA-2064-1

Produtos afetados

Firefox
Seamonkey