CVE-2010-1203
published 2010-06-24CVE-2010-1203: The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or…
PriorityP433critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.87%
89.1th percentile
The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger an assertion failure in jstracer.cpp.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_ubuntu10.0CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and Xulrunner vulnerability
vendor_ubuntu·2010-07-26·CVSS 10.0
CVE-2010-2755 [CRITICAL] Firefox and Xulrunner vulnerability
Title: Firefox and Xulrunner vulnerability
Summary: Firefox could be made to run programs as your login if it opened a
specially crafted file or website.
USN-957-1 fixed vulnerabilities in Firefox and Xulrunner. Daniel Holbert
discovered that the fix for CVE-2010-1214 introduced a regression which did
not properly initialize a plugin pointer. If a user were tricked into
viewing a malicious site, a remote attacker could use this to crash the
browser or run arbitrary code as the user invoking the program.
(CVE-2010-2755)
This update fixes the problem.
Original advisory details:
If was discovered that Firefox could be made to access freed memory. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2010-07-23·CVSS 9.8
CVE-2008-5913 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox could be made to run programs as your login if it opened a
specially crafted file or website.
USN-930-1 fixed vulnerabilities in Firefox and Xulrunner. This update
provides the corresponding updates for Ubuntu 9.04 and 9.10, along with
additional updates affecting Firefox 3.6.6.
Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious site, a remote attacker could use
this to crash the browser or possibly run arbitrary code as the user
invoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,
CVE-2010-1212)
An integer overflow was discovered in how Firefox processed plugin
parameters. An attacker could exploit this to crash the browser or possibly
run arbitrary
Ubuntu
ant, apturl, Epiphany, gluezilla, gnome-python-extras, liferea, mozvoikko, OpenJDK, packagekit, ubufox, webfav, yelp update
vendor_ubuntu·2010-07-23·CVSS 10.0
[CRITICAL] ant, apturl, Epiphany, gluezilla, gnome-python-extras, liferea, mozvoikko, OpenJDK, packagekit, ubufox, webfav, yelp update
Title: ant, apturl, Epiphany, gluezilla, gnome-python-extras, liferea, mozvoikko, OpenJDK, packagekit, ubufox, webfav, yelp update
Summary: This update is for use with the new Xulrunner provided in USN-930-4.
USN-930-4 fixed vulnerabilities in Firefox and Xulrunner on Ubuntu 9.04 and
9.10. This update provides updated packages for use with Firefox 3.6 and
Xulrunner 1.9.2.
Original advisory details:
If was discovered that Firefox could be made to access freed memory. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS. (CVE-2010-1121)
Several flaws were discovered in the browser engine of Firefox. If a
user
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2010-07-06·CVSS 10.0
CVE-2010-1199 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Martin Barbella discovered an integer overflow in an XSLT node sorting
routine. An attacker could exploit this to overflow a buffer and cause a
denial of service or possibly execute arbitrary code with the privileges of
the user invoking the program. (CVE-2010-1199)
An integer overflow was discovered in Thunderbird. If a user were tricked
into viewing malicious content, an attacker could overflow a buffer and
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-1196)
Several flaws were discovered in the browser engine of Thunderbird. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
pr
Ubuntu
Firefox regression
vendor_ubuntu·2010-06-30·CVSS 10.0
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: This update fixes a problem with Firefox not installing alongside the old
Firefox 2 package.
USN-930-1 fixed vulnerabilities in Firefox. Due to a software packaging
problem, the Firefox 3.6 update could not be installed when the firefox-2
package was also installed. This update fixes the problem and updates
apturl for the change.
Original advisory details:
If was discovered that Firefox could be made to access freed memory. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS. (CVE-2010-1121)
Several flaws were discovered in the browser engine of Firefox. If a
user were tr
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2010-06-29·CVSS 10.0
CVE-2010-1121 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox could be made to run programs as your login if it opened a
specially crafted file or website.
If was discovered that Firefox could be made to access freed memory. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS. (CVE-2010-1121)
Several flaws were discovered in the browser engine of Firefox. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,
CVE-2010-1202, CVE-2010-1203)
A
Ubuntu
apturl, Epiphany, gecko-sharp, gnome-python-extras, liferea, rhythmbox, totem, ubufox, yelp update
vendor_ubuntu·2010-06-29·CVSS 10.0
[CRITICAL] apturl, Epiphany, gecko-sharp, gnome-python-extras, liferea, rhythmbox, totem, ubufox, yelp update
Title: apturl, Epiphany, gecko-sharp, gnome-python-extras, liferea, rhythmbox, totem, ubufox, yelp update
Summary: This update is for use with the new Xulrunner provided in USN-930-1.
USN-930-1 fixed vulnerabilities in Firefox and Xulrunner. This update
provides updated packages for use with Firefox 3.6 and Xulrunner 1.9.2 on
Ubuntu 8.04 LTS.
Original advisory details:
If was discovered that Firefox could be made to access freed memory. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS. (CVE-2010-1121)
Several flaws were discovered in the browser engine of Firefox. If a
user were tricked into viewing a m
Red Hat
Mozilla Crashes with evidence of memory corruption
vendor_redhat·2010-06-22·CVSS 9.3
CVE-2010-1203 [CRITICAL] Mozilla Crashes with evidence of memory corruption
Mozilla Crashes with evidence of memory corruption
The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger an assertion failure in jstracer.cpp.
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Red Hat
cacti: XSS issues in host.php and data_sources.php (VUPEN/ADV-2010-1203)
vendor_redhat·2010-05-20·CVSS 4.3
CVE-2010-1644 [MEDIUM] CWE-79 cacti: XSS issues in host.php and data_sources.php (VUPEN/ADV-2010-1203)
cacti: XSS issues in host.php and data_sources.php (VUPEN/ADV-2010-1203)
Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) hostname or (2) description parameter to host.php, or (3) the host_id parameter to data_sources.php.
GHSA
GHSA-vrcw-32cf-52wm: The JavaScript engine in Mozilla Firefox 3
ghsa_unreviewed·2022-05-02
CVE-2010-1203 [HIGH] GHSA-vrcw-32cf-52wm: The JavaScript engine in Mozilla Firefox 3
The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger an assertion failure in jstracer.cpp.
Suricata
ET WEB_SERVER Possible Cisco Adaptive Security Appliance Web VPN FTP or CIFS Authentication Form Phishing Attempt
suricata·2010-07-30
CVE-2009-1203 ET WEB_SERVER Possible Cisco Adaptive Security Appliance Web VPN FTP or CIFS Authentication Form Phishing Attempt
ET WEB_SERVER Possible Cisco Adaptive Security Appliance Web VPN FTP or CIFS Authentication Form Phishing Attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SERVER Possible Cisco Adaptive Security Appliance Web VPN FTP or CIFS Authentication Form Phishing Attempt"; flow:established,to_server; http.uri; content:"+CSCOE+/files/browse.html"; nocase; fast_pattern; content:"code=init"; nocase; distance:0; content:"path=ftp"; nocase; distance:0; reference:url,www.securityfocus.com/bid/35475/info; reference:cve,2009-1203; classtype:attempted-user; sid:2010457; rev:9; metadata:attack_target Client_Endpoint, created_at 2010_07_30, cve CVE_2009_1203, deployment Perimeter, confidence Medium, signature_severity Major, tag Phishing, updated_at 2020_11_07;)
No public exploits indexed.
Bugzilla
CVE-2010-1644 cacti: XSS issues in host.php and data_sources.php (VUPEN/ADV-2010-1203)
bugzilla·2010-06-29·CVSS 4.3
CVE-2010-1644 [MEDIUM] CVE-2010-1644 cacti: XSS issues in host.php and data_sources.php (VUPEN/ADV-2010-1203)
CVE-2010-1644 cacti: XSS issues in host.php and data_sources.php (VUPEN/ADV-2010-1203)
Multiple XSS issues were discovered in Cacti and fixed in version 0.8.7f:
- host.php via "hostname" and "description" parameters
- data_sources.php via "host_id" parameter
References:
http://www.vupen.com/english/advisories/2010/1203
http://www.cacti.net/release_notes_0_8_7f.php
Upstream commit:
http://svn.cacti.net/viewvc?view=rev&revision=5901
Discussion:
This issue has been addressed in following products:
Red Hat HPC Solution for RHEL 5
Via RHSA-2010:0635 https://rhn.redhat.com/errata/RHSA-2010-0635.html
Bugzilla
CVE-2010-1644 CVE-2010-1645 CVE-2010-2092 Cacti v0.8.7f - three security fixes
bugzilla·2010-05-24·CVSS 4.3
CVE-2010-1644 [MEDIUM] CVE-2010-1644 CVE-2010-1645 CVE-2010-2092 Cacti v0.8.7f - three security fixes
CVE-2010-1644 CVE-2010-1645 CVE-2010-2092 Cacti v0.8.7f - three security fixes
Cacti upstream has released:
[1] http://www.cacti.net/release_notes_0_8_7f.php
latest v0.8.7 version, addressing three security flaws:
[A], MOPS-2010-023: Cacti Graph Viewer SQL Injection Vulnerability
[2] http://php-security.org/2010/05/13/mops-2010-023-cacti-graph-viewer-sql-injection-vulnerability/index.html
[3] http://www.vupen.com/english/advisories/2010/1204
Credit: The vulnerability was discovered by Stefan Esser as part
of the SQL Injection Marathon.
Upstream changeset:
[4] http://svn.cacti.net/viewvc?view=rev&revision=5920
[B], Cross-site scripting issues reported by VUPEN Security
(http://www.vupen.com)
[5] http://www.vupen.com/english/advisories/2010/1203
Credit: Vulnerabilities reported by Moham
Bugzilla
CVE-2010-1203 Mozilla Crashes with evidence of memory corruption
bugzilla·2010-05-10·CVSS 9.3
CVE-2010-1203 [CRITICAL] CVE-2010-1203 Mozilla Crashes with evidence of memory corruption
CVE-2010-1203 Mozilla Crashes with evidence of memory corruption
Mozilla developers identified and fixed several stability bugs in the
browser engine used in Firefox and other Mozilla-based products. Some of
these crashes showed evidence of memory corruption under certain
circumstances, and we presume that with enough effort at least some of
these could be exploited to run arbitrary code.
Gary Kwong and David Anderson reported crashes in the JavaScript engine
that affected Firefox 3.6 only.
Discussion:
This issue is now public:
http://www.mozilla.org/security/announce/2010/mfsa2010-26.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Via RHSA-2010:0500 https://rhn.redhat.com/errata/RHSA-2010-0500.html
---
This issue has been addressed in fo
http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.htmlhttp://secunia.com/advisories/40323http://secunia.com/advisories/40326http://secunia.com/advisories/40401http://secunia.com/advisories/40481http://support.avaya.com/css/P8/documents/100091069http://ubuntu.com/usn/usn-930-1http://www.mandriva.com/security/advisories?name=MDVSA-2010:125http://www.mozilla.org/security/announce/2010/mfsa2010-26.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0500.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0501.htmlhttp://www.securityfocus.com/bid/41050http://www.securityfocus.com/bid/41099http://www.securitytracker.com/id?1024138http://www.securitytracker.com/id?1024139http://www.ubuntu.com/usn/usn-930-2http://www.vupen.com/english/advisories/2010/1551http://www.vupen.com/english/advisories/2010/1557http://www.vupen.com/english/advisories/2010/1640http://www.vupen.com/english/advisories/2010/1773https://bugzilla.mozilla.org/show_bug.cgi?id=546611https://bugzilla.mozilla.org/show_bug.cgi?id=557946https://exchange.xforce.ibmcloud.com/vulnerabilities/59662https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10401https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8317http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.htmlhttp://secunia.com/advisories/40323http://secunia.com/advisories/40326http://secunia.com/advisories/40401http://secunia.com/advisories/40481http://support.avaya.com/css/P8/documents/100091069http://ubuntu.com/usn/usn-930-1http://www.mandriva.com/security/advisories?name=MDVSA-2010:125http://www.mozilla.org/security/announce/2010/mfsa2010-26.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0500.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0501.htmlhttp://www.securityfocus.com/bid/41050http://www.securityfocus.com/bid/41099http://www.securitytracker.com/id?1024138http://www.securitytracker.com/id?1024139http://www.ubuntu.com/usn/usn-930-2http://www.vupen.com/english/advisories/2010/1551http://www.vupen.com/english/advisories/2010/1557http://www.vupen.com/english/advisories/2010/1640http://www.vupen.com/english/advisories/2010/1773https://bugzilla.mozilla.org/show_bug.cgi?id=546611https://bugzilla.mozilla.org/show_bug.cgi?id=557946https://exchange.xforce.ibmcloud.com/vulnerabilities/59662https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10401https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8317
2010-06-24
Published