CVE-2010-0174
published 2010-04-05CVE-2010-0174: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before…
PriorityP336critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.97%
92.5th percentile
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Affected
190 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.5.7 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox 3.0 and Xulrunner vulnerabilities
vendor_ubuntu·2010-04-09·CVSS 10.0
CVE-2010-0174 [CRITICAL] Firefox 3.0 and Xulrunner vulnerabilities
Title: Firefox 3.0 and Xulrunner vulnerabilities
Summary: Firefox 3.0 and Xulrunner vulnerabilities
Martijn Wargers, Josh Soref, Jesse Ruderman, and Ehsan Akhgari discovered
flaws in the browser engine of Firefox. If a user were tricked into viewing
a malicious website, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2010-0174)
It was discovered that Firefox could be made to access previously freed
memory. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0175,
CVE-2010-0176, CVE-2010-0177)
Paul Stone discovered that Firefox could be made
Ubuntu
Firefox 3.5 and Xulrunner vulnerabilities
vendor_ubuntu·2010-04-09·CVSS 9.3
CVE-2010-0182 [CRITICAL] Firefox 3.5 and Xulrunner vulnerabilities
Title: Firefox 3.5 and Xulrunner vulnerabilities
Summary: Firefox 3.5 and Xulrunner vulnerabilities
Martijn Wargers, Josh Soref, Jesse Ruderman, and Ehsan Akhgari discovered
flaws in the browser engine of Firefox. If a user were tricked into viewing
a malicious website, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2010-0173, CVE-2010-0174)
It was discovered that Firefox could be made to access previously freed
memory. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0175,
CVE-2010-0176, CVE-2010-0177)
Paul Stone discovered that Firefo
Red Hat
Mozilla crashes with evidence of memory corruption
vendor_redhat·2010-03-30·CVSS 10.0
CVE-2010-0174 [CRITICAL] Mozilla crashes with evidence of memory corruption
Mozilla crashes with evidence of memory corruption
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
VulDB
Mozilla Firefox up to 1.0.8 Browser Engine memory corruption (Bug 546530 / Nessus ID 68066)
vuldb·2026-05-05·CVSS 10.0
CVE-2010-0174 [CRITICAL] Mozilla Firefox up to 1.0.8 Browser Engine memory corruption (Bug 546530 / Nessus ID 68066)
A vulnerability was found in Mozilla Firefox and classified as critical. This affects an unknown function of the component Browser Engine. Executing a manipulation can lead to memory corruption.
This vulnerability appears as CVE-2010-0174. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
GHSA-v6hg-x8c9-r375: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2010-0174 [HIGH] GHSA-v6hg-x8c9-r375: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038378.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038406.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/38566http://secunia.com/advisories/39117http://secunia.com/advisories/39136http://secunia.com/advisories/39204http://secunia.com/advisories/39240http://secunia.com/advisories/39242http://secunia.com/advisories/39243http://secunia.com/advisories/39308http://secunia.com/advisories/39397http://securitytracker.com/id?1023775http://securitytracker.com/id?1023781http://ubuntu.com/usn/usn-921-1http://www.debian.org/security/2010/dsa-2027http://www.mandriva.com/security/advisories?name=MDVSA-2010:070http://www.mozilla.org/security/announce/2010/mfsa2010-16.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0332.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0333.htmlhttp://www.vupen.com/english/advisories/2010/0748http://www.vupen.com/english/advisories/2010/0764http://www.vupen.com/english/advisories/2010/0765http://www.vupen.com/english/advisories/2010/0781http://www.vupen.com/english/advisories/2010/0790http://www.vupen.com/english/advisories/2010/0849https://bugzilla.mozilla.org/show_bug.cgi?id=499844https://bugzilla.mozilla.org/show_bug.cgi?id=546530https://exchange.xforce.ibmcloud.com/vulnerabilities/57389https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7615https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9502http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038378.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038406.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/38566http://secunia.com/advisories/39117http://secunia.com/advisories/39136http://secunia.com/advisories/39204http://secunia.com/advisories/39240http://secunia.com/advisories/39242http://secunia.com/advisories/39243http://secunia.com/advisories/39308http://secunia.com/advisories/39397http://securitytracker.com/id?1023775http://securitytracker.com/id?1023781http://ubuntu.com/usn/usn-921-1http://www.debian.org/security/2010/dsa-2027http://www.mandriva.com/security/advisories?name=MDVSA-2010:070http://www.mozilla.org/security/announce/2010/mfsa2010-16.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0332.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0333.htmlhttp://www.vupen.com/english/advisories/2010/0748http://www.vupen.com/english/advisories/2010/0764http://www.vupen.com/english/advisories/2010/0765http://www.vupen.com/english/advisories/2010/0781http://www.vupen.com/english/advisories/2010/0790http://www.vupen.com/english/advisories/2010/0849https://bugzilla.mozilla.org/show_bug.cgi?id=499844https://bugzilla.mozilla.org/show_bug.cgi?id=546530https://exchange.xforce.ibmcloud.com/vulnerabilities/57389https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7615https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9502
2010-04-05
Published