PT-2010-4267 · Mozilla+2 · Firefox+4

Reed

·

Published

2010-07-20

·

Updated

2024-12-12

·

CVE-2010-2753

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 3.5.x through 3.5.10 Mozilla Firefox versions 3.6.x through 3.6.6 Thunderbird versions 3.0.x through 3.0.5 Thunderbird versions 3.1.x through 3.1.0 SeaMonkey version 2.0.5 and earlier
Description The issue allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free. This occurs due to an integer overflow in the affected software.
Recommendations For Mozilla Firefox versions 3.5.x through 3.5.10, update to version 3.5.11 or later. For Mozilla Firefox versions 3.6.x through 3.6.6, update to version 3.6.7 or later. For Thunderbird versions 3.0.x through 3.0.5, update to version 3.0.6 or later. For Thunderbird versions 3.1.x through 3.1.0, update to version 3.1.1 or later. For SeaMonkey version 2.0.5 and earlier, update to version 2.0.6 or later.

Exploit

Fix

RCE

Integer Overflow

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2753
DSA-2075-1
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:14572-1
RHSA-2010:0544
RHSA-2010:0545
RHSA-2010:0546
RHSA-2010:0547
RHSA-2010_0544
RHSA-2010_0545
RHSA-2010_0546
RHSA-2010_0547
ZDI-10-131

Affected Products

Firefox
Red Hat
Seamonkey
Suse
Thunderbird