CVE-2010-0160
published 2010-02-22CVE-2010-0160: The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data…
PriorityP337critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.01%
92.6th percentile
The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.17 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla implementation of Web Workers can lead to crash with evidence of memory corruption (MFSA 2010-02)
vendor_redhat·2010-02-17·CVSS 10.0
CVE-2010-0160 [CRITICAL] Mozilla implementation of Web Workers can lead to crash with evidence of memory corruption (MFSA 2010-02)
Mozilla implementation of Web Workers can lead to crash with evidence of memory corruption (MFSA 2010-02)
The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
Ubuntu
Firefox 3.0 and Xulrunner 1.9 vulnerabilities
vendor_ubuntu·2010-02-17·CVSS 10.0
CVE-2010-0159 [CRITICAL] Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Title: Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Summary: Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious website, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-0159)
Orlando Barrera II discovered a flaw in the Web Workers implementation of
Firefox. If a user were tricked into posting to a malicious website, an
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0160)
Alin Rad Pop discovered that Firefox's HTML parser would incorrectly free
memory under certain circumstances. If the bro
Ubuntu
Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
vendor_ubuntu·2010-02-17·CVSS 10.0
CVE-2010-0160 [CRITICAL] Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Title: Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Summary: Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious website, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-0159)
Orlando Barrera II discovered a flaw in the Web Workers implementation of
Firefox. If a user were tricked into posting to a malicious website, an
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0160)
Alin Rad Pop discovered that Firefox's HTML parser would incorrectly free
memory under certain circumstances. If the
VulDB
Mozilla SeaMonkey up to 2.0.2 Web Worker resource management (Nessus ID 44648 / ID 118843)
vuldb·2026-05-01·CVSS 10.0
CVE-2010-0160 [CRITICAL] Mozilla SeaMonkey up to 2.0.2 Web Worker resource management (Nessus ID 44648 / ID 118843)
A vulnerability, which was classified as critical, has been found in Mozilla SeaMonkey. This issue affects some unknown processing of the component Web Worker. This manipulation causes improper resource management.
This vulnerability appears as CVE-2010-0160. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
GHSA
GHSA-jpcj-8f59-9q4h: The Web Worker functionality in Mozilla Firefox 3
ghsa_unreviewed·2022-05-02
CVE-2010-0160 [HIGH] GHSA-jpcj-8f59-9q4h: The Web Worker functionality in Mozilla Firefox 3
The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.htmlhttp://secunia.com/advisories/37242http://secunia.com/advisories/38847http://www.debian.org/security/2010/dsa-1999http://www.mandriva.com/security/advisories?name=MDVSA-2010:042http://www.mozilla.org/security/announce/2010/mfsa2010-02.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0112.htmlhttp://www.securityfocus.com/archive/1/510533/100/0/threadedhttp://www.ubuntu.com/usn/USN-895-1http://www.ubuntu.com/usn/USN-896-1http://www.vupen.com/english/advisories/2010/0405http://www.zerodayinitiative.com/advisories/ZDI-10-046https://bugzilla.mozilla.org/show_bug.cgi?id=531222https://bugzilla.mozilla.org/show_bug.cgi?id=533000https://bugzilla.mozilla.org/show_bug.cgi?id=534051https://exchange.xforce.ibmcloud.com/vulnerabilities/56360https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11166https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8465http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.htmlhttp://secunia.com/advisories/37242http://secunia.com/advisories/38847http://www.debian.org/security/2010/dsa-1999http://www.mandriva.com/security/advisories?name=MDVSA-2010:042http://www.mozilla.org/security/announce/2010/mfsa2010-02.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0112.htmlhttp://www.securityfocus.com/archive/1/510533/100/0/threadedhttp://www.ubuntu.com/usn/USN-895-1http://www.ubuntu.com/usn/USN-896-1http://www.vupen.com/english/advisories/2010/0405http://www.zerodayinitiative.com/advisories/ZDI-10-046https://bugzilla.mozilla.org/show_bug.cgi?id=531222https://bugzilla.mozilla.org/show_bug.cgi?id=533000https://bugzilla.mozilla.org/show_bug.cgi?id=534051https://exchange.xforce.ibmcloud.com/vulnerabilities/56360https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11166https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8465
2010-02-22
Published