PT-2010-4269 · Mozilla+1 · Firefox+1

Daniel Holbert

+1

·

Publicado

2010-07-24

·

Atualizado

2024-12-12

·

CVE-2010-2755

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox version 3.6.7
Description The issue is related to the improper freeing of memory in the parameter array of a plugin instance, which can be exploited by remote attackers through a crafted HTML document. This is specifically tied to the DATA and SRC attributes of an OBJECT element, potentially leading to memory corruption or the execution of arbitrary code.
Recommendations For Mozilla Firefox version 3.6.7, update to a version that properly addresses the memory freeing issue in the parameter array of plugin instances to prevent potential memory corruption or arbitrary code execution.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2755
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
RHSA-2010:0556
RHSA-2010:0557
RHSA-2010:0558
RHSA-2010_0556
RHSA-2010_0557
RHSA-2010_0558

Produtos afetados

Firefox
Red Hat