PT-2010-4269 · Mozilla+1 · Firefox+1

Daniel Holbert

+1

·

Published

2010-07-24

·

Updated

2024-12-12

·

CVE-2010-2755

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox version 3.6.7
Description The issue is related to the improper freeing of memory in the parameter array of a plugin instance, which can be exploited by remote attackers through a crafted HTML document. This is specifically tied to the DATA and SRC attributes of an OBJECT element, potentially leading to memory corruption or the execution of arbitrary code.
Recommendations For Mozilla Firefox version 3.6.7, update to a version that properly addresses the memory freeing issue in the parameter array of plugin instances to prevent potential memory corruption or arbitrary code execution.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2755
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
RHSA-2010:0556
RHSA-2010:0557
RHSA-2010:0558
RHSA-2010_0556
RHSA-2010_0557
RHSA-2010_0558

Affected Products

Firefox
Red Hat