Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-5074 | First vendor Publication | 2011-12-07 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The layout engine in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 executes different code for visited and unvisited links during the processing of Cascading Style Sheets (CSS) token sequences, which makes it easier for remote attackers to obtain sensitive information about visited web pages via a timing attack. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5074 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-362 | Race Condition |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:14456 | |||
Oval ID: | oval:org.mitre.oval:def:14456 | ||
Title: | The layout engine in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 executes different code for visited and unvisited links during the processing of Cascading Style Sheets (CSS) token sequences, which makes it easier for remote attackers to obtain sensitive information about visited web pages via a timing attack. | ||
Description: | The layout engine in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 executes different code for visited and unvisited links during the processing of Cascading Style Sheets (CSS) token sequences, which makes it easier for remote attackers to obtain sensitive information about visited web pages via a timing attack. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-5074 | Version: | 15 |
Platform(s): | Microsoft Windows 7 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows Server 2003 Microsoft Windows XP Microsoft Windows 2000 | Product(s): | Mozilla Thunderbird Mozilla Seamonkey |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2011-12-09 | Name : Mozilla Products Multiple Information Disclosure Vulnerabilities - MAC OS X File : nvt/gb_mozilla_prdts_mult_info_disc_vuln_macosx.nasl |
2011-12-09 | Name : Mozilla Products Multiple Information Disclosure Vulnerabilities - (Windows) File : nvt/gb_mozilla_prdts_mult_info_disc_vuln_win.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
77609 | Mozilla Multiple Product CSS Token Sequence Parsing Timing Attack Remote Info... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-01-08 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201301-01.nasl - Type : ACT_GATHER_INFO |
2011-12-15 | Name : The remote Windows host contains a web browser that is affected by an informa... File : mozilla_firefox_40.nasl - Type : ACT_GATHER_INFO |
2011-12-15 | Name : The remote Windows host contains a web browser that may be affected by an inf... File : seamonkey_21.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2025-02-07 01:16:18 |
|
2024-11-28 23:03:25 |
|
2024-11-28 12:24:09 |
|
2024-11-01 01:15:30 |
|
2024-10-22 12:15:26 |
|
2024-08-02 12:15:22 |
|
2024-08-02 01:04:15 |
|
2024-02-10 01:13:54 |
|
2024-02-02 01:14:55 |
|
2024-02-01 12:04:10 |
|
2023-09-05 12:13:57 |
|
2023-09-05 01:04:02 |
|
2023-09-02 12:14:00 |
|
2023-09-02 01:04:05 |
|
2023-08-12 12:16:48 |
|
2023-08-12 01:04:06 |
|
2023-08-11 12:14:05 |
|
2023-08-11 01:04:13 |
|
2023-08-06 12:13:32 |
|
2023-08-06 01:04:07 |
|
2023-08-04 12:13:37 |
|
2023-08-04 01:04:07 |
|
2023-07-14 12:13:34 |
|
2023-07-14 01:04:05 |
|
2023-04-01 01:11:32 |
|
2023-03-29 01:15:31 |
|
2023-03-28 12:04:11 |
|
2022-10-11 12:12:06 |
|
2022-10-11 01:03:52 |
|
2021-05-04 12:13:16 |
|
2021-04-22 01:13:47 |
|
2020-10-14 01:06:03 |
|
2020-10-03 01:06:03 |
|
2020-05-29 01:05:33 |
|
2020-05-23 01:43:30 |
|
2020-05-23 00:27:22 |
|
2019-06-25 12:03:22 |
|
2019-01-31 12:01:23 |
|
2019-01-30 12:03:36 |
|
2018-07-13 01:03:44 |
|
2018-01-18 12:03:43 |
|
2017-11-22 12:03:40 |
|
2017-11-21 12:02:52 |
|
2017-09-19 09:24:07 |
|
2016-06-28 18:27:18 |
|
2016-04-26 20:24:02 |
|
2014-02-17 10:59:11 |
|
2013-05-10 23:40:55 |
|