PT-2010-4613 · Mozilla+2 · Firefox+4

:Reed

+1

·

Published

2010-09-08

·

Updated

2024-12-12

·

CVE-2010-3168

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.5.12 and 3.6.x prior to 3.6.9 Thunderbird versions prior to 3.0.7 and 3.1.x prior to 3.1.3 SeaMonkey versions prior to 2.0.7
Description The issue allows remote attackers to cause a denial of service or possibly execute arbitrary code by setting unspecified properties, due to improper restriction of the role of property changes in triggering XUL tree removal. This can lead to deleted memory access and application crash.
Recommendations For Mozilla Firefox versions prior to 3.5.12 and 3.6.x prior to 3.6.9, update to a version that includes the fix for this issue. For Thunderbird versions prior to 3.0.7 and 3.1.x prior to 3.1.3, update to a version that includes the fix for this issue. For SeaMonkey versions prior to 2.0.7, update to a version that includes the fix for this issue.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3168
DSA-2106-1
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:14572-1
RHSA-2010:0680
RHSA-2010:0681
RHSA-2010:0682
RHSA-2010_0680
RHSA-2010_0681
RHSA-2010_0682
ZDI-10-172

Affected Products

Firefox
Red Hat
Seamonkey
Suse
Thunderbird