← Zuruck zu CVEs
CVE-2010-2753
HIGH8.8
Beschreibung
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free.
CVE Details
CVSS v3.1 Bewertung8.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht7/30/2010
Zuletzt geandert4/29/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
mozilla:firefoxmozilla:seamonkeymozilla:thunderbirdopensuse:opensusesuse:linux_enterprise_desktopsuse:linux_enterprise_serversuse:linux_enterprise_software_development_kit
Schwachen (CWE)
CWE-190CWE-416
Referenzen
http://www.securityfocus.com/archive/1/512510(cve@mitre.org)
http://www.securityfocus.com/bid/41853(cve@mitre.org)
http://www.zerodayinitiative.com/advisories/ZDI-10-131/(cve@mitre.org)
https://bugzilla.mozilla.org/show_bug.cgi?id=571106(cve@mitre.org)
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10958(cve@mitre.org)
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00002.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.mozilla.org/security/announce/2010/mfsa2010-40.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/archive/1/512510(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/41853(af854a3a-2127-422b-91ae-364da2661108)
http://www.zerodayinitiative.com/advisories/ZDI-10-131/(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.mozilla.org/show_bug.cgi?id=571106(af854a3a-2127-422b-91ae-364da2661108)
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10958(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.