CVE-2010-0181
published 2010-04-05CVE-2010-0181: Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, executes a mail application in situations where an IMG element has a SRC…
PriorityP412medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.22%
80.8th percentile
Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many images.
Affected
130 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.5.7 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q66x-vm73-35xj: Opera 9
ghsa_unreviewed·2022-05-14·CVSS 4.3
CVE-2010-1989 [MEDIUM] GHSA-q66x-vm73-35xj: Opera 9
Opera 9.52 executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many images, a related issue to CVE-2010-0181.
GHSA
GHSA-545x-w2c3-gjv5: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2010-0181 [MEDIUM] CWE-20 GHSA-545x-w2c3-gjv5: Mozilla Firefox before 3
Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many images.
Ubuntu
Firefox 3.5 and Xulrunner vulnerabilities
vendor_ubuntu·2010-04-09·CVSS 9.3
CVE-2010-0182 [CRITICAL] Firefox 3.5 and Xulrunner vulnerabilities
Title: Firefox 3.5 and Xulrunner vulnerabilities
Summary: Firefox 3.5 and Xulrunner vulnerabilities
Martijn Wargers, Josh Soref, Jesse Ruderman, and Ehsan Akhgari discovered
flaws in the browser engine of Firefox. If a user were tricked into viewing
a malicious website, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2010-0173, CVE-2010-0174)
It was discovered that Firefox could be made to access previously freed
memory. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0175,
CVE-2010-0176, CVE-2010-0177)
Paul Stone discovered that Firefo
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4643 OpenOffice.org: heap based buffer overflow when parsing TGA files
bugzilla·2011-01-06·CVSS 9.3
CVE-2010-4643 [CRITICAL] CVE-2010-4643 OpenOffice.org: heap based buffer overflow when parsing TGA files
CVE-2010-4643 OpenOffice.org: heap based buffer overflow when parsing TGA files
A heap-based buffer overflow was discovered in various versions of
OpenOffice.org, when reading certain TGA files.
If a user opened a specially crafted TGA file, it could lead to
application crash or possibly execution of arbitrary code, with
the privileges of the user running OpenOffice.org Impress.
This has been assigned CVE-2010-4643.
Acknowledgements:
Red Hat would like to thank OpenOffice.org for reporting this issue.
Discussion:
Public via:
http://www.openoffice.org/security/cves/CVE-2010-4643.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Via RHSA-2011:0181 https://rhn.redhat.com/errata/RHSA-2011-0181.html
---
This issue has been addressed in followi
Bugzilla
CVE-2008-3279 brltty: insecure relative RPATH
bugzilla·2008-08-05·CVSS 6.9
CVE-2008-3279 [MEDIUM] CVE-2008-3279 brltty: insecure relative RPATH
CVE-2008-3279 brltty: insecure relative RPATH
brltty packages as shipped in Red Hat Enterprise Linux 5 are built with an
insecure RPATH set in the ELF header of one of the libraries shipped in the
package.
This issue can possibly be exploited by a local attacker to run arbitrary code
as some other user if victim user can be convinced to run command using affected library in an attacker controlled directory with specially crafted content.
Affected binary: /usr/lib/brltty/libbrlttybba.so
RPATH: ../../Programs
Discussion:
This issue does not affect brltty 3.8 and 3.9 packages currently shipped in Fedora.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0181 https://rhn.redhat.com/errata/RHSA-2010-0181.html
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/39136http://secunia.com/advisories/39397http://ubuntu.com/usn/usn-921-1http://websecurity.com.ua/4206/http://www.mandriva.com/security/advisories?name=MDVSA-2010:070http://www.mozilla.org/security/announce/2010/mfsa2010-23.htmlhttp://www.securityfocus.com/archive/1/511327/100/0/threadedhttp://www.vupen.com/english/advisories/2010/0748http://www.vupen.com/english/advisories/2010/0849https://bugzilla.mozilla.org/show_bug.cgi?id=452093https://exchange.xforce.ibmcloud.com/vulnerabilities/57395https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6776http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/39136http://secunia.com/advisories/39397http://ubuntu.com/usn/usn-921-1http://websecurity.com.ua/4206/http://www.mandriva.com/security/advisories?name=MDVSA-2010:070http://www.mozilla.org/security/announce/2010/mfsa2010-23.htmlhttp://www.securityfocus.com/archive/1/511327/100/0/threadedhttp://www.vupen.com/english/advisories/2010/0748http://www.vupen.com/english/advisories/2010/0849https://bugzilla.mozilla.org/show_bug.cgi?id=452093https://exchange.xforce.ibmcloud.com/vulnerabilities/57395https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6776
2010-04-05
Published