CVE-2010-0220
published 2010-01-07CVE-2010-0220: The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of…
PriorityP416medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.46%
71.1th percentile
The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.
Affected
68 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.5.6 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
: Firefox DoS (crash) via crafted web site that triggers memory consumption
vendor_redhat·2009-07-29·CVSS 5.0
CVE-2010-0220 [MEDIUM] : Firefox DoS (crash) via crafted web site that triggers memory consumption
: Firefox DoS (crash) via crafted web site that triggers memory consumption
The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.
GHSA
GHSA-35p6-jmhj-fg2v: The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList
ghsa_unreviewed·2022-05-02
CVE-2010-0220 [MEDIUM] GHSA-35p6-jmhj-fg2v: The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList
The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.
No detection rules found.
http://hg.mozilla.org/mozilla-central/rev/51396f6c9f20http://isc.sans.org/diary.html?storyid=7897http://www.mandriva.com/security/advisories?name=MDVSA-2010:000http://www.mozilla.com/en-US/firefox/3.5.7/releasenotes/https://bugzilla.mozilla.org/show_bug.cgi?id=507114https://exchange.xforce.ibmcloud.com/vulnerabilities/55550https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8292http://hg.mozilla.org/mozilla-central/rev/51396f6c9f20http://isc.sans.org/diary.html?storyid=7897http://www.mandriva.com/security/advisories?name=MDVSA-2010:000http://www.mozilla.com/en-US/firefox/3.5.7/releasenotes/https://bugzilla.mozilla.org/show_bug.cgi?id=507114https://exchange.xforce.ibmcloud.com/vulnerabilities/55550https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8292
2010-01-07
Published