CVE-2010-1121Code Injection in Mozilla Firefox

CWE-94Code Injection11 documents5 sources
Severity
10.0CRITICALNVD
EPSS
4.7%
top 10.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 25
Latest updateMay 2

Description

Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote attackers to conduct use-after-free attacks and execute arbitrary code via unspecified vectors involving improper interaction with garbage collection, as demonstrated by Nils during a Pwn2Own competition at CanSecWest 2010.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDmozilla/firefox3.6, 3.6.1, 3.6.2+2

🔴Vulnerability Details

1
GHSA
GHSA-7jg2-5jh7-2mjr: Mozilla Firefox 32022-05-02

📋Vendor Advisories

8
Ubuntu
Firefox and Xulrunner vulnerability2010-07-26
Ubuntu
Firefox and Xulrunner vulnerabilities2010-07-23
Ubuntu
ant, apturl, Epiphany, gluezilla, gnome-python-extras, liferea, mozvoikko, OpenJDK, packagekit, ubufox, webfav, yelp update2010-07-23
Ubuntu
Thunderbird vulnerabilities2010-07-06
Ubuntu
Firefox regression2010-06-30

💬Community

1
Bugzilla
CVE-2010-1121 firefox: arbitrary code execution via memory corruption2010-03-25