CVE-2010-0178
published 2010-04-05CVE-2010-0178: Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mouse clicks…
PriorityP335high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
3.43%
87.6th percentile
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mouse clicks as drag-and-drop actions, which allows remote attackers to execute arbitrary JavaScript with Chrome privileges by loading a chrome: URL and then loading a javascript: URL.
Affected
129 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.17 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_ubuntu10.0CRITICAL
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox 3.0 and Xulrunner vulnerabilities
vendor_ubuntu·2010-04-09·CVSS 10.0
CVE-2010-0174 [CRITICAL] Firefox 3.0 and Xulrunner vulnerabilities
Title: Firefox 3.0 and Xulrunner vulnerabilities
Summary: Firefox 3.0 and Xulrunner vulnerabilities
Martijn Wargers, Josh Soref, Jesse Ruderman, and Ehsan Akhgari discovered
flaws in the browser engine of Firefox. If a user were tricked into viewing
a malicious website, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2010-0174)
It was discovered that Firefox could be made to access previously freed
memory. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0175,
CVE-2010-0176, CVE-2010-0177)
Paul Stone discovered that Firefox could be made
Ubuntu
Firefox 3.5 and Xulrunner vulnerabilities
vendor_ubuntu·2010-04-09·CVSS 9.3
CVE-2010-0182 [CRITICAL] Firefox 3.5 and Xulrunner vulnerabilities
Title: Firefox 3.5 and Xulrunner vulnerabilities
Summary: Firefox 3.5 and Xulrunner vulnerabilities
Martijn Wargers, Josh Soref, Jesse Ruderman, and Ehsan Akhgari discovered
flaws in the browser engine of Firefox. If a user were tricked into viewing
a malicious website, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2010-0173, CVE-2010-0174)
It was discovered that Firefox could be made to access previously freed
memory. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0175,
CVE-2010-0176, CVE-2010-0177)
Paul Stone discovered that Firefo
Red Hat
Firefox Chrome privilege escalation via forced URL drag and drop
vendor_redhat·2010-03-30·CVSS 7.6
CVE-2010-0178 [HIGH] Firefox Chrome privilege escalation via forced URL drag and drop
Firefox Chrome privilege escalation via forced URL drag and drop
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mouse clicks as drag-and-drop actions, which allows remote attackers to execute arbitrary JavaScript with Chrome privileges by loading a chrome: URL and then loading a javascript: URL.
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
VulDB
Mozilla Firefox up to 1.0.8 code injection (Bug 546909 / Nessus ID 45443)
vuldb·2026-05-05·CVSS 7.6
CVE-2010-0178 [HIGH] Mozilla Firefox up to 1.0.8 code injection (Bug 546909 / Nessus ID 45443)
A vulnerability categorized as critical has been discovered in Mozilla Firefox. Affected by this issue is some unknown functionality. Such manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2010-0178. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
GHSA
GHSA-8m7g-3wf3-3hff: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2010-0178 [HIGH] CWE-94 GHSA-8m7g-3wf3-3hff: Mozilla Firefox before 3
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mouse clicks as drag-and-drop actions, which allows remote attackers to execute arbitrary JavaScript with Chrome privileges by loading a chrome: URL and then loading a javascript: URL.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-0178 Firefox Chrome privilege escalation via forced URL drag and drop
bugzilla·2010-03-30·CVSS 7.6
CVE-2010-0178 [HIGH] CVE-2010-0178 Firefox Chrome privilege escalation via forced URL drag and drop
CVE-2010-0178 Firefox Chrome privilege escalation via forced URL drag and drop
Security researcher Paul Stone reported that a browser applet could be used
to turn a simple mouse click into a drag-and-drop action, potentially
resulting in the unintended loading of resources in a user's browser. This
behavior could be used twice in succession to first load a privileged
chrome: URL in a victim's browser, then load a malicious javascript: URL on
top of the same document resulting in arbitrary script execution with
chrome privileges.
This flaw does not affect the version of SeaMonkey shipped in Red Hat
Enterprise Linux 3 or 4.
Discussion:
This is now public
http://www.mozilla.org/security/announce/2010/mfsa2010-20.html
---
This issue has been addressed in following products:
Red Hat Ente
Bugzilla
CVE-2009-4307 kernel: ext4: avoid divide by zero when trying to mount a corrupted file system
bugzilla·2009-12-14·CVSS 7.1
CVE-2009-4307 [HIGH] CVE-2009-4307 kernel: ext4: avoid divide by zero when trying to mount a corrupted file system
CVE-2009-4307 kernel: ext4: avoid divide by zero when trying to mount a corrupted file system
Description of problem:
ext4: avoid divide by zero when trying to mount a corrupted file system
If s_log_groups_per_flex is greater than 31, then groups_per_flex will overflow and cause a divide by zero error. This can cause kernel BUG if such a file system is mounted.
Upstream commit:
http://git.kernel.org/linus/503358ae01b70ce6909d19dd01287093f6b6271c
References:
http://bugzilla.kernel.org/show_bug.cgi?id=14287
http://secunia.com/advisories/37658
Discussion:
Created attachment 378143
corrupted image for this issue
---
Patch present on the current RHEL6 git tree.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0178 https://rhn.redhat.c
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/39136http://secunia.com/advisories/39240http://secunia.com/advisories/39243http://secunia.com/advisories/39308http://secunia.com/advisories/39397http://securitytracker.com/id?1023776http://ubuntu.com/usn/usn-921-1http://www.debian.org/security/2010/dsa-2027http://www.mandriva.com/security/advisories?name=MDVSA-2010:070http://www.mozilla.org/security/announce/2010/mfsa2010-20.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0332.htmlhttp://www.vupen.com/english/advisories/2010/0748http://www.vupen.com/english/advisories/2010/0764http://www.vupen.com/english/advisories/2010/0781http://www.vupen.com/english/advisories/2010/0849https://bugzilla.mozilla.org/show_bug.cgi?id=546909https://exchange.xforce.ibmcloud.com/vulnerabilities/57391https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10460https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6975http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/39136http://secunia.com/advisories/39240http://secunia.com/advisories/39243http://secunia.com/advisories/39308http://secunia.com/advisories/39397http://securitytracker.com/id?1023776http://ubuntu.com/usn/usn-921-1http://www.debian.org/security/2010/dsa-2027http://www.mandriva.com/security/advisories?name=MDVSA-2010:070http://www.mozilla.org/security/announce/2010/mfsa2010-20.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0332.htmlhttp://www.vupen.com/english/advisories/2010/0748http://www.vupen.com/english/advisories/2010/0764http://www.vupen.com/english/advisories/2010/0781http://www.vupen.com/english/advisories/2010/0849https://bugzilla.mozilla.org/show_bug.cgi?id=546909https://exchange.xforce.ibmcloud.com/vulnerabilities/57391https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10460https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6975
2010-04-05
Published