PT-2010-4269 · Mozilla+1 · Firefox+1
Daniel Holbert
+1
·
Publicado
2010-07-24
·
Atualizado
2024-12-12
·
CVE-2010-2755
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox version 3.6.7
Description
The issue is related to the improper freeing of memory in the parameter array of a plugin instance, which can be exploited by remote attackers through a crafted HTML document. This is specifically tied to the DATA and SRC attributes of an OBJECT element, potentially leading to memory corruption or the execution of arbitrary code.
Recommendations
For Mozilla Firefox version 3.6.7, update to a version that properly addresses the memory freeing issue in the parameter array of plugin instances to prevent potential memory corruption or arbitrary code execution.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Firefox
Red Hat