CVE-2010-0177
published 2010-04-05CVE-2010-0177: Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plugins array…
PriorityP339critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
7.00%
93.4th percentile
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plugins array while a reference to an array element is still active, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, related to a "dangling pointer vulnerability."
Affected
129 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.17 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_ubuntu10.0CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox 3.0 and Xulrunner vulnerabilities
vendor_ubuntu·2010-04-09·CVSS 10.0
CVE-2010-0174 [CRITICAL] Firefox 3.0 and Xulrunner vulnerabilities
Title: Firefox 3.0 and Xulrunner vulnerabilities
Summary: Firefox 3.0 and Xulrunner vulnerabilities
Martijn Wargers, Josh Soref, Jesse Ruderman, and Ehsan Akhgari discovered
flaws in the browser engine of Firefox. If a user were tricked into viewing
a malicious website, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2010-0174)
It was discovered that Firefox could be made to access previously freed
memory. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0175,
CVE-2010-0176, CVE-2010-0177)
Paul Stone discovered that Firefox could be made
Ubuntu
Firefox 3.5 and Xulrunner vulnerabilities
vendor_ubuntu·2010-04-09·CVSS 9.3
CVE-2010-0182 [CRITICAL] Firefox 3.5 and Xulrunner vulnerabilities
Title: Firefox 3.5 and Xulrunner vulnerabilities
Summary: Firefox 3.5 and Xulrunner vulnerabilities
Martijn Wargers, Josh Soref, Jesse Ruderman, and Ehsan Akhgari discovered
flaws in the browser engine of Firefox. If a user were tricked into viewing
a malicious website, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2010-0173, CVE-2010-0174)
It was discovered that Firefox could be made to access previously freed
memory. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0175,
CVE-2010-0176, CVE-2010-0177)
Paul Stone discovered that Firefo
Red Hat
Mozilla Dangling pointer vulnerability in nsPluginArray
vendor_redhat·2010-03-30·CVSS 9.3
CVE-2010-0177 [CRITICAL] Mozilla Dangling pointer vulnerability in nsPluginArray
Mozilla Dangling pointer vulnerability in nsPluginArray
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plugins array while a reference to an array element is still active, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, related to a "dangling pointer vulnerability."
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
VulDB
Mozilla Firefox up to 1.0.8 window.navigator.plugins resource management (Bug 538310 / Nessus ID 45443)
vuldb·2026-05-05·CVSS 9.3
CVE-2010-0177 [CRITICAL] Mozilla Firefox up to 1.0.8 window.navigator.plugins resource management (Bug 538310 / Nessus ID 45443)
A vulnerability was found in Mozilla Firefox. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the file window.navigator.plugins. This manipulation causes improper resource management.
This vulnerability is handled as CVE-2010-0177. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-g4x4-8fj2-6pwg: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2010-0177 [HIGH] GHSA-g4x4-8fj2-6pwg: Mozilla Firefox before 3
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plugins array while a reference to an array element is still active, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, related to a "dangling pointer vulnerability."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-1814 webkit: memory corruption flaw when handling form menus
bugzilla·2010-09-08·CVSS 6.8
CVE-2010-1814 [MEDIUM] CVE-2010-1814 webkit: memory corruption flaw when handling form menus
CVE-2010-1814 webkit: memory corruption flaw when handling form menus
A memory corruption issue exists in WebKit's handling of form menus. Visiting a
maliciously crafted website may lead to an unexpected application termination
or arbitrary code execution. This issue is fixed through improved handling of
form menus. Credit to Csaba Osztrogonac of University of Szeged for reporting
this issue.
References:
https://bugs.webkit.org/show_bug.cgi?id=40828
http://trac.webkit.org/changeset/61709
http://support.apple.com/kb/HT4334
Discussion:
This issue has been corrected in WebKitGTK 1.2.5.
---
Created webkitgtk tracking bugs for this issue
Affects: fedora-all [bug 640382]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0177 https://rhn
Bugzilla
CVE-2010-1815 webkit: use-after-free flaw when handling scrollbars
bugzilla·2010-09-08·CVSS 6.8
CVE-2010-1815 [MEDIUM] CVE-2010-1815 webkit: use-after-free flaw when handling scrollbars
CVE-2010-1815 webkit: use-after-free flaw when handling scrollbars
A use after free issue exists in WebKit's handling of scrollbars. Visiting
a maliciously crafted website may lead to an unexpected application
termination or arbitrary code execution. This issue is addressed through
improved memory management. Credit to Tony Chang of Google, Inc for
reporting this issue.
References:
https://bugs.webkit.org/show_bug.cgi?id=41196
http://trac.webkit.org/changeset/63138
http://support.apple.com/kb/HT4334
Discussion:
This issue has been corrected in WebKitGTK 1.2.5.
---
Created webkitgtk tracking bugs for this issue
Affects: fedora-all [bug 640382]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0177 https://rhn.redhat.com/errata/RHSA
Bugzilla
CVE-2010-1812 webkit: use-after-free flaw in handling of selections
bugzilla·2010-09-08·CVSS 6.8
CVE-2010-1812 [MEDIUM] CVE-2010-1812 webkit: use-after-free flaw in handling of selections
CVE-2010-1812 webkit: use-after-free flaw in handling of selections
A use after free issue exists in WebKit's handling of selections. Visiting
a maliciously crafted website may lead to an unexpected application
termination or arbitrary code execution. This issue is addressed through
improved handling of selections. Credit to Ojan Vafai of Google, Inc. for
reporting this issue.
References:
https://bugs.webkit.org/show_bug.cgi?id=41523
http://trac.webkit.org/changeset/62873
Discussion:
Public via http://support.apple.com/kb/HT4334
---
This issue has been corrected in WebKitGTK 1.2.5.
---
Created webkitgtk tracking bugs for this issue
Affects: fedora-all [bug 640382]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0177 https://rh
Bugzilla
CVE-2010-0177 Mozilla Dangling pointer vulnerability in nsPluginArray
bugzilla·2010-03-30·CVSS 9.3
CVE-2010-0177 [CRITICAL] CVE-2010-0177 Mozilla Dangling pointer vulnerability in nsPluginArray
CVE-2010-0177 Mozilla Dangling pointer vulnerability in nsPluginArray
Security researcher regenrecht reported via TippingPoint's Zero Day
Initiative an error in the implementation of the window.navigator.plugins
object. When a page reloads, the plugins array would reallocate all of its
members without checking for existing references to each member. This could
result in the deletion of objects for which valid pointers still exist. An
attacker could use this vulnerability to crash a victim's browser and run
arbitrary code on the victim's machine.
Discussion:
This is now public
http://www.mozilla.org/security/announce/2010/mfsa2010-19.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 3
Via RHSA-2010:0333 https://rhn.redha
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/38566http://secunia.com/advisories/39117http://secunia.com/advisories/39136http://secunia.com/advisories/39240http://secunia.com/advisories/39243http://secunia.com/advisories/39308http://secunia.com/advisories/39397http://securitytracker.com/id?1023776http://ubuntu.com/usn/usn-921-1http://www.debian.org/security/2010/dsa-2027http://www.mandriva.com/security/advisories?name=MDVSA-2010:070http://www.mozilla.org/security/announce/2010/mfsa2010-19.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0332.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0333.htmlhttp://www.securityfocus.com/archive/1/510540/100/0/threadedhttp://www.vupen.com/english/advisories/2010/0748http://www.vupen.com/english/advisories/2010/0764http://www.vupen.com/english/advisories/2010/0765http://www.vupen.com/english/advisories/2010/0781http://www.vupen.com/english/advisories/2010/0849http://www.zerodayinitiative.com/advisories/ZDI-10-049https://bugzilla.mozilla.org/show_bug.cgi?id=538310https://exchange.xforce.ibmcloud.com/vulnerabilities/57393https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10833https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7622http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/38566http://secunia.com/advisories/39117http://secunia.com/advisories/39136http://secunia.com/advisories/39240http://secunia.com/advisories/39243http://secunia.com/advisories/39308http://secunia.com/advisories/39397http://securitytracker.com/id?1023776http://ubuntu.com/usn/usn-921-1http://www.debian.org/security/2010/dsa-2027http://www.mandriva.com/security/advisories?name=MDVSA-2010:070http://www.mozilla.org/security/announce/2010/mfsa2010-19.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0332.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0333.htmlhttp://www.securityfocus.com/archive/1/510540/100/0/threadedhttp://www.vupen.com/english/advisories/2010/0748http://www.vupen.com/english/advisories/2010/0764http://www.vupen.com/english/advisories/2010/0765http://www.vupen.com/english/advisories/2010/0781http://www.vupen.com/english/advisories/2010/0849http://www.zerodayinitiative.com/advisories/ZDI-10-049https://bugzilla.mozilla.org/show_bug.cgi?id=538310https://exchange.xforce.ibmcloud.com/vulnerabilities/57393https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10833https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7622
2010-04-05
Published