Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-3769 | First vendor Publication | 2010-12-10 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3769 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:12342 | |||
Oval ID: | oval:org.mitre.oval:def:12342 | ||
Title: | Buffer overflow vulnerability in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Mozilla Thunderbird before 3.0.11 and 3.1.x before 3.1.7 and Mozilla SeaMonkey before 2.0.11 | ||
Description: | The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-3769 | Version: | 21 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows XP | Product(s): | Mozilla Firefox Mozilla SeaMonkey Mozilla Thunderbird |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2011-01-24 | Name : Debian Security Advisory DSA 2132-1 (xulrunner) File : nvt/deb_2132_1.nasl |
2011-01-24 | Name : FreeBSD Ports: firefox File : nvt/freebsd_firefox53.nasl |
2011-01-11 | Name : SuSE Update for MozillaFirefox,MozillaThunderbird,Seamonkey SUSE-SA:2011:003 File : nvt/gb_suse_2011_003.nasl |
2010-12-28 | Name : Mandriva Update for firefox MDVSA-2010:251-1 (firefox) File : nvt/gb_mandriva_MDVSA_2010_251_1.nasl |
2010-12-28 | Name : Mandriva Update for firefox MDVSA-2010:251-2 (firefox) File : nvt/gb_mandriva_MDVSA_2010_251_2.nasl |
2010-12-28 | Name : Mandriva Update for mozilla-thunderbird MDVSA-2010:258 (mozilla-thunderbird) File : nvt/gb_mandriva_MDVSA_2010_258.nasl |
2010-12-27 | Name : Mozilla Products Multiple Vulnerabilities dec-10 (Windows) File : nvt/gb_mozilla_prdts_mult_vuln_win_dec10.nasl |
2010-12-23 | Name : Mandriva Update for firefox MDVSA-2010:251 (firefox) File : nvt/gb_mandriva_MDVSA_2010_251.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
69771 | Mozilla Multiple Products Line-breaking document.write Call Arbitrary Code Ex... Mozilla Firefox, Thunderbird and SeaMonkey contain a flaw related to the line-breaking implementation's handling of long strings. The issue is triggered when a context-dependent attacker uses a maliciously crafted document.write call to trigger a buffer over-read. This will allow the execution of arbitrary code. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : suse_11_3_seamonkey-101213.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : suse_11_3_mozilla-xulrunner191-101213.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : suse_11_3_MozillaThunderbird-101213.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : suse_11_3_MozillaFirefox-101213.nasl - Type : ACT_GATHER_INFO |
2013-01-08 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201301-01.nasl - Type : ACT_GATHER_INFO |
2011-05-05 | Name : The remote openSUSE host is missing a security update. File : suse_11_1_MozillaThunderbird-101213.nasl - Type : ACT_GATHER_INFO |
2011-05-05 | Name : The remote openSUSE host is missing a security update. File : suse_11_2_seamonkey-101213.nasl - Type : ACT_GATHER_INFO |
2011-05-05 | Name : The remote openSUSE host is missing a security update. File : suse_11_2_mozilla-xulrunner191-101213.nasl - Type : ACT_GATHER_INFO |
2011-05-05 | Name : The remote openSUSE host is missing a security update. File : suse_11_2_MozillaThunderbird-101213.nasl - Type : ACT_GATHER_INFO |
2011-05-05 | Name : The remote openSUSE host is missing a security update. File : suse_11_2_MozillaFirefox-101213.nasl - Type : ACT_GATHER_INFO |
2011-05-05 | Name : The remote openSUSE host is missing a security update. File : suse_11_1_seamonkey-101213.nasl - Type : ACT_GATHER_INFO |
2011-05-05 | Name : The remote openSUSE host is missing a security update. File : suse_11_1_mozilla-xulrunner191-101212.nasl - Type : ACT_GATHER_INFO |
2011-05-05 | Name : The remote openSUSE host is missing a security update. File : suse_11_1_MozillaFirefox-101212.nasl - Type : ACT_GATHER_INFO |
2011-01-21 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_MozillaFirefox-101213.nasl - Type : ACT_GATHER_INFO |
2011-01-21 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_mozilla-xulrunner191-101213.nasl - Type : ACT_GATHER_INFO |
2011-01-04 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_MozillaFirefox-7280.nasl - Type : ACT_GATHER_INFO |
2010-12-23 | Name : The remote Fedora host is missing a security update. File : fedora_2010-18920.nasl - Type : ACT_GATHER_INFO |
2010-12-23 | Name : The remote Fedora host is missing a security update. File : fedora_2010-18890.nasl - Type : ACT_GATHER_INFO |
2010-12-21 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2010-258.nasl - Type : ACT_GATHER_INFO |
2010-12-15 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2132.nasl - Type : ACT_GATHER_INFO |
2010-12-12 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_1d8ff4a2044511e08e32000f20797ede.nasl - Type : ACT_GATHER_INFO |
2010-12-10 | Name : The remote Windows host contains a web browser affected by multiple vulnerabi... File : seamonkey_2011.nasl - Type : ACT_GATHER_INFO |
2010-12-10 | Name : The remote Windows host contains a mail client that is affected by multiple v... File : mozilla_thunderbird_317.nasl - Type : ACT_GATHER_INFO |
2010-12-10 | Name : The remote Windows host contains a mail client that is affected by multiple v... File : mozilla_thunderbird_3011.nasl - Type : ACT_GATHER_INFO |
2010-12-10 | Name : The remote Windows host contains a web browser affected by multiple vulnerabi... File : mozilla_firefox_3613.nasl - Type : ACT_GATHER_INFO |
2010-12-10 | Name : The remote Windows host contains a web browser affected by multiple vulnerabi... File : mozilla_firefox_3516.nasl - Type : ACT_GATHER_INFO |
2010-12-10 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2010-251.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2025-02-07 01:15:33 |
|
2024-11-28 23:06:44 |
|
2024-11-28 12:23:10 |
|
2024-11-01 01:14:49 |
|
2024-10-22 12:14:45 |
|
2024-08-02 12:14:38 |
|
2024-08-02 01:04:00 |
|
2024-02-10 01:13:15 |
|
2024-02-02 01:14:12 |
|
2024-02-01 12:03:55 |
|
2023-09-05 12:13:14 |
|
2023-09-05 01:03:47 |
|
2023-09-02 12:13:19 |
|
2023-09-02 01:03:50 |
|
2023-08-12 12:15:49 |
|
2023-08-12 01:03:49 |
|
2023-08-11 12:13:21 |
|
2023-08-11 01:03:58 |
|
2023-08-06 12:12:50 |
|
2023-08-06 01:03:51 |
|
2023-08-04 12:12:56 |
|
2023-08-04 01:03:52 |
|
2023-07-14 12:12:53 |
|
2023-07-14 01:03:50 |
|
2023-03-29 01:14:45 |
|
2023-03-28 12:03:56 |
|
2022-10-11 12:11:29 |
|
2022-10-11 01:03:37 |
|
2020-10-14 01:05:46 |
|
2020-10-03 01:05:46 |
|
2020-05-29 01:05:16 |
|
2020-05-23 01:42:49 |
|
2020-05-23 00:26:39 |
|
2019-06-25 12:03:14 |
|
2019-01-30 12:03:28 |
|
2018-07-13 01:03:36 |
|
2017-11-22 12:03:32 |
|
2017-11-21 12:02:44 |
|
2017-09-19 09:24:01 |
|
2016-06-28 18:20:21 |
|
2016-04-26 20:09:19 |
|
2014-06-14 13:29:29 |
|
2014-02-17 10:57:55 |
|
2013-05-10 23:34:30 |
|