CVE-2010-0162
published 2010-02-22CVE-2010-0162: Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.96%
85.7th percentile
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as a protection mechanism against execution of web script in certain circumstances involving SVG and the EMBED element, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via an embedded SVG document.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox 3.0 and Xulrunner 1.9 vulnerabilities
vendor_ubuntu·2010-02-17·CVSS 10.0
CVE-2010-0159 [CRITICAL] Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Title: Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Summary: Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious website, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-0159)
Orlando Barrera II discovered a flaw in the Web Workers implementation of
Firefox. If a user were tricked into posting to a malicious website, an
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0160)
Alin Rad Pop discovered that Firefox's HTML parser would incorrectly free
memory under certain circumstances. If the bro
Ubuntu
Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
vendor_ubuntu·2010-02-17·CVSS 10.0
CVE-2010-0160 [CRITICAL] Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Title: Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Summary: Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious website, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-0159)
Orlando Barrera II discovered a flaw in the Web Workers implementation of
Firefox. If a user were tricked into posting to a malicious website, an
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0160)
Alin Rad Pop discovered that Firefox's HTML parser would incorrectly free
memory under certain circumstances. If the
Red Hat
Mozilla bypass of same-origin policy due to improper SVG document processing (MFSA 2010-05)
vendor_redhat·2010-02-17·CVSS 4.3
CVE-2010-0162 [MEDIUM] Mozilla bypass of same-origin policy due to improper SVG document processing (MFSA 2010-05)
Mozilla bypass of same-origin policy due to improper SVG document processing (MFSA 2010-05)
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as a protection mechanism against execution of web script in certain circumstances involving SVG and the EMBED element, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via an embedded SVG document.
VulDB
Mozilla SeaMonkey up to 2.0.2 Same Origin Policy cross site scripting (Bug 455472 / Nessus ID 44648)
vuldb·2026-05-01·CVSS 4.3
CVE-2010-0162 [MEDIUM] Mozilla SeaMonkey up to 2.0.2 Same Origin Policy cross site scripting (Bug 455472 / Nessus ID 44648)
A vulnerability, which was classified as problematic, was found in Mozilla SeaMonkey. Impacted is an unknown function of the component Same Origin Policy. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2010-0162. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
GHSA
GHSA-g94q-cc43-mm5v: Mozilla Firefox 3
ghsa_unreviewed·2022-05-02
CVE-2010-0162 [MEDIUM] CWE-79 GHSA-g94q-cc43-mm5v: Mozilla Firefox 3
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as a protection mechanism against execution of web script in certain circumstances involving SVG and the EMBED element, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via an embedded SVG document.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path [rhel-4.8.z]
bugzilla·2010-12-03·CVSS 6.2
CVE-2010-4258 [MEDIUM] CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path [rhel-4.8.z]
CVE-2010-4258 kernel: failure to revert address limit override in OOPS error path [rhel-4.8.z]
A patch addressing this issue has been included in kernel 2.6.9-89.34.1.EL.
Discussion:
Reproduced in 2.6.9-89.33.EL and -89.34.EL. Verified in 2.6.9-89.34.1.EL.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2011-0162.html
Bugzilla
CVE-2010-0162 Mozilla bypass of same-origin policy due to improper SVG document processing (MFSA 2010-05)
bugzilla·2010-02-17·CVSS 4.3
CVE-2010-0162 [MEDIUM] CVE-2010-0162 Mozilla bypass of same-origin policy due to improper SVG document processing (MFSA 2010-05)
CVE-2010-0162 Mozilla bypass of same-origin policy due to improper SVG document processing (MFSA 2010-05)
Mozilla security researcher Georgi Guninski reported that when a SVG document
which is served with Content-Type: application/octet-stream is embedded into
another document via an tag with type="image/svg+xml", the Content-Type
is ignored and the SVG document is processed normally. A website which allows
arbitrary binary data to be uploaded but which relies on Content-Type:
application/octet-stream to prevent script execution could have such protection
bypassed. An attacker could upload a SVG document containing JavaScript as a
binary file to a website, embed the SVG document into a malicous page on
another site, and gain access to the script environment from the SVG-serving
site, bypa
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.htmlhttp://secunia.com/advisories/37242http://secunia.com/advisories/38847http://www.debian.org/security/2010/dsa-1999http://www.mandriva.com/security/advisories?name=MDVSA-2010:042http://www.mozilla.org/security/announce/2010/mfsa2010-05.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0112.htmlhttp://www.ubuntu.com/usn/USN-895-1http://www.ubuntu.com/usn/USN-896-1http://www.vupen.com/english/advisories/2010/0405https://bugzilla.mozilla.org/show_bug.cgi?id=455472https://exchange.xforce.ibmcloud.com/vulnerabilities/56363https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10697https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8631http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.htmlhttp://secunia.com/advisories/37242http://secunia.com/advisories/38847http://www.debian.org/security/2010/dsa-1999http://www.mandriva.com/security/advisories?name=MDVSA-2010:042http://www.mozilla.org/security/announce/2010/mfsa2010-05.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0112.htmlhttp://www.ubuntu.com/usn/USN-895-1http://www.ubuntu.com/usn/USN-896-1http://www.vupen.com/english/advisories/2010/0405https://bugzilla.mozilla.org/show_bug.cgi?id=455472https://exchange.xforce.ibmcloud.com/vulnerabilities/56363https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10697https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8631
2010-02-22
Published