PT-2010-1997 · Mozilla · Firefox+1

Wushi

·

Published

2010-06-23

·

Updated

2017-09-19

·

CVE-2010-0183

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 3.5.x through 3.5.9 SeaMonkey versions prior to 2.0.5
Description A use-after-free issue exists in the nsCycleCollector::MarkRoots function, related to an improper frame construction process for menus. This allows remote attackers to execute arbitrary code via a crafted HTML document.
Recommendations For Mozilla Firefox versions 3.5.x through 3.5.9, update to version 3.5.10 or later. For SeaMonkey versions prior to 2.0.5, update to version 2.0.5 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-0183
DSA-2064-1

Affected Products

Firefox
Seamonkey