PT-2010-4269 · Mozilla+1 · Firefox+1
Daniel Holbert
+1
·
Published
2010-07-24
·
Updated
2024-12-12
·
CVE-2010-2755
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox version 3.6.7
Description
The issue is related to the improper freeing of memory in the parameter array of a plugin instance, which can be exploited by remote attackers through a crafted HTML document. This is specifically tied to the DATA and SRC attributes of an OBJECT element, potentially leading to memory corruption or the execution of arbitrary code.
Recommendations
For Mozilla Firefox version 3.6.7, update to a version that properly addresses the memory freeing issue in the parameter array of plugin instances to prevent potential memory corruption or arbitrary code execution.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox
Red Hat