CVE-2010-0175
published 2010-04-05CVE-2010-0175: Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and…
PriorityP335critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
7.05%
93.5th percentile
Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.
Affected
189 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.17 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_ubuntu10.0CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox 3.0 and Xulrunner vulnerabilities
vendor_ubuntu·2010-04-09·CVSS 10.0
CVE-2010-0174 [CRITICAL] Firefox 3.0 and Xulrunner vulnerabilities
Title: Firefox 3.0 and Xulrunner vulnerabilities
Summary: Firefox 3.0 and Xulrunner vulnerabilities
Martijn Wargers, Josh Soref, Jesse Ruderman, and Ehsan Akhgari discovered
flaws in the browser engine of Firefox. If a user were tricked into viewing
a malicious website, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2010-0174)
It was discovered that Firefox could be made to access previously freed
memory. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0175,
CVE-2010-0176, CVE-2010-0177)
Paul Stone discovered that Firefox could be made
Ubuntu
Firefox 3.5 and Xulrunner vulnerabilities
vendor_ubuntu·2010-04-09·CVSS 9.3
CVE-2010-0182 [CRITICAL] Firefox 3.5 and Xulrunner vulnerabilities
Title: Firefox 3.5 and Xulrunner vulnerabilities
Summary: Firefox 3.5 and Xulrunner vulnerabilities
Martijn Wargers, Josh Soref, Jesse Ruderman, and Ehsan Akhgari discovered
flaws in the browser engine of Firefox. If a user were tricked into viewing
a malicious website, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2010-0173, CVE-2010-0174)
It was discovered that Firefox could be made to access previously freed
memory. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0175,
CVE-2010-0176, CVE-2010-0177)
Paul Stone discovered that Firefo
Red Hat
Mozilla remote code execution with use-after-free in nsTreeSelection
vendor_redhat·2010-03-30·CVSS 9.3
CVE-2010-0175 [CRITICAL] CWE-416 Mozilla remote code execution with use-after-free in nsTreeSelection
Mozilla remote code execution with use-after-free in nsTreeSelection
Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
VulDB
Mozilla Firefox up to 1.0.8 resource management (Bug 540100 / Nessus ID 45443)
vuldb·2026-05-05·CVSS 9.3
CVE-2010-0175 [CRITICAL] Mozilla Firefox up to 1.0.8 resource management (Bug 540100 / Nessus ID 45443)
A vulnerability was found in Mozilla Firefox. It has been classified as critical. This impacts an unknown function. The manipulation leads to improper resource management.
This vulnerability is traded as CVE-2010-0175. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-f74m-jmww-q4m2: Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2010-0175 [HIGH] GHSA-f74m-jmww-q4m2: Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3
Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038378.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038406.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/38566http://secunia.com/advisories/39117http://secunia.com/advisories/39136http://secunia.com/advisories/39204http://secunia.com/advisories/39240http://secunia.com/advisories/39242http://secunia.com/advisories/39243http://secunia.com/advisories/39308http://secunia.com/advisories/39397http://securitytracker.com/id?1023780http://securitytracker.com/id?1023782http://ubuntu.com/usn/usn-921-1http://www.debian.org/security/2010/dsa-2027http://www.mandriva.com/security/advisories?name=MDVSA-2010:070http://www.mozilla.org/security/announce/2010/mfsa2010-17.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0332.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0333.htmlhttp://www.securityfocus.com/archive/1/510542/100/0/threadedhttp://www.vupen.com/english/advisories/2010/0748http://www.vupen.com/english/advisories/2010/0764http://www.vupen.com/english/advisories/2010/0765http://www.vupen.com/english/advisories/2010/0781http://www.vupen.com/english/advisories/2010/0790http://www.vupen.com/english/advisories/2010/0849http://www.zerodayinitiative.com/advisories/ZDI-10-050https://bugzilla.mozilla.org/show_bug.cgi?id=375928https://bugzilla.mozilla.org/show_bug.cgi?id=540100https://exchange.xforce.ibmcloud.com/vulnerabilities/57390https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7546https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9834http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038378.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038406.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/38566http://secunia.com/advisories/39117http://secunia.com/advisories/39136http://secunia.com/advisories/39204http://secunia.com/advisories/39240http://secunia.com/advisories/39242http://secunia.com/advisories/39243http://secunia.com/advisories/39308http://secunia.com/advisories/39397http://securitytracker.com/id?1023780http://securitytracker.com/id?1023782http://ubuntu.com/usn/usn-921-1http://www.debian.org/security/2010/dsa-2027http://www.mandriva.com/security/advisories?name=MDVSA-2010:070http://www.mozilla.org/security/announce/2010/mfsa2010-17.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0332.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0333.htmlhttp://www.securityfocus.com/archive/1/510542/100/0/threadedhttp://www.vupen.com/english/advisories/2010/0748http://www.vupen.com/english/advisories/2010/0764http://www.vupen.com/english/advisories/2010/0765http://www.vupen.com/english/advisories/2010/0781http://www.vupen.com/english/advisories/2010/0790http://www.vupen.com/english/advisories/2010/0849http://www.zerodayinitiative.com/advisories/ZDI-10-050https://bugzilla.mozilla.org/show_bug.cgi?id=375928https://bugzilla.mozilla.org/show_bug.cgi?id=540100https://exchange.xforce.ibmcloud.com/vulnerabilities/57390https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7546https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9834
2010-04-05
Published