CVE-2010-0176
published 2010-04-05CVE-2010-0176: Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage…
PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.20%
91.6th percentile
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to deleted elements, related to a "dangling pointer vulnerability."
Affected
190 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.5.7 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_ubuntu10.0CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Firefox up to 1.0.8 resource management (Bug 538308 / Nessus ID 45443)
vuldb·2026-05-05·CVSS 9.3
CVE-2010-0176 [CRITICAL] Mozilla Firefox up to 1.0.8 resource management (Bug 538308 / Nessus ID 45443)
A vulnerability was found in Mozilla Firefox. It has been declared as critical. Affected is an unknown function. The manipulation results in improper resource management.
This vulnerability is known as CVE-2010-0176. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
GHSA
GHSA-wcmh-4pfq-jg4p: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2010-0176 [HIGH] GHSA-wcmh-4pfq-jg4p: Mozilla Firefox before 3
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to deleted elements, related to a "dangling pointer vulnerability."
Ubuntu
Firefox 3.0 and Xulrunner vulnerabilities
vendor_ubuntu·2010-04-09·CVSS 10.0
CVE-2010-0174 [CRITICAL] Firefox 3.0 and Xulrunner vulnerabilities
Title: Firefox 3.0 and Xulrunner vulnerabilities
Summary: Firefox 3.0 and Xulrunner vulnerabilities
Martijn Wargers, Josh Soref, Jesse Ruderman, and Ehsan Akhgari discovered
flaws in the browser engine of Firefox. If a user were tricked into viewing
a malicious website, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2010-0174)
It was discovered that Firefox could be made to access previously freed
memory. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0175,
CVE-2010-0176, CVE-2010-0177)
Paul Stone discovered that Firefox could be made
Ubuntu
Firefox 3.5 and Xulrunner vulnerabilities
vendor_ubuntu·2010-04-09·CVSS 9.3
CVE-2010-0182 [CRITICAL] Firefox 3.5 and Xulrunner vulnerabilities
Title: Firefox 3.5 and Xulrunner vulnerabilities
Summary: Firefox 3.5 and Xulrunner vulnerabilities
Martijn Wargers, Josh Soref, Jesse Ruderman, and Ehsan Akhgari discovered
flaws in the browser engine of Firefox. If a user were tricked into viewing
a malicious website, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2010-0173, CVE-2010-0174)
It was discovered that Firefox could be made to access previously freed
memory. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0175,
CVE-2010-0176, CVE-2010-0177)
Paul Stone discovered that Firefo
Red Hat
Mozilla Dangling pointer vulnerability in nsTreeContentView
vendor_redhat·2010-03-30·CVSS 9.3
CVE-2010-0176 [CRITICAL] Mozilla Dangling pointer vulnerability in nsTreeContentView
Mozilla Dangling pointer vulnerability in nsTreeContentView
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to deleted elements, related to a "dangling pointer vulnerability."
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038378.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038406.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/38566http://secunia.com/advisories/39117http://secunia.com/advisories/39136http://secunia.com/advisories/39204http://secunia.com/advisories/39240http://secunia.com/advisories/39242http://secunia.com/advisories/39243http://secunia.com/advisories/39308http://secunia.com/advisories/39397http://securitytracker.com/id?1023776http://securitytracker.com/id?1023782http://ubuntu.com/usn/usn-921-1http://www.debian.org/security/2010/dsa-2027http://www.mandriva.com/security/advisories?name=MDVSA-2010:070http://www.mozilla.org/security/announce/2010/mfsa2010-18.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0332.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0333.htmlhttp://www.vupen.com/english/advisories/2010/0748http://www.vupen.com/english/advisories/2010/0764http://www.vupen.com/english/advisories/2010/0765http://www.vupen.com/english/advisories/2010/0781http://www.vupen.com/english/advisories/2010/0790http://www.vupen.com/english/advisories/2010/0849https://bugzilla.mozilla.org/show_bug.cgi?id=538308https://exchange.xforce.ibmcloud.com/vulnerabilities/57392https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11052https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7222http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038378.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038406.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/38566http://secunia.com/advisories/39117http://secunia.com/advisories/39136http://secunia.com/advisories/39204http://secunia.com/advisories/39240http://secunia.com/advisories/39242http://secunia.com/advisories/39243http://secunia.com/advisories/39308http://secunia.com/advisories/39397http://securitytracker.com/id?1023776http://securitytracker.com/id?1023782http://ubuntu.com/usn/usn-921-1http://www.debian.org/security/2010/dsa-2027http://www.mandriva.com/security/advisories?name=MDVSA-2010:070http://www.mozilla.org/security/announce/2010/mfsa2010-18.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0332.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0333.htmlhttp://www.vupen.com/english/advisories/2010/0748http://www.vupen.com/english/advisories/2010/0764http://www.vupen.com/english/advisories/2010/0765http://www.vupen.com/english/advisories/2010/0781http://www.vupen.com/english/advisories/2010/0790http://www.vupen.com/english/advisories/2010/0849https://bugzilla.mozilla.org/show_bug.cgi?id=538308https://exchange.xforce.ibmcloud.com/vulnerabilities/57392https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11052https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7222
2010-04-05
Published