CVE-2010-2753
published 2010-07-30CVE-2010-2753: Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before…
PriorityP343high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
6.67%
93.1th percentile
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free.
Affected
207 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.5.11 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_ubuntu10.0CRITICAL
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
SquirrelMail: CSRF in the empty trash feature and in Index Order page
vendor_redhat·2011-07-12·CVSS 4.3
CVE-2011-2753 [MEDIUM] CWE-352 SquirrelMail: CSRF in the empty trash feature and in Index Order page
SquirrelMail: CSRF in the empty trash feature and in Index Order page
Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to hijack the authentication of unspecified victims via vectors involving (1) the empty trash implementation and (2) the Index Order (aka options_order) page, a different issue than CVE-2010-4555.
Red Hat
Mozilla Dangling pointer vulnerability in nsTreeSelection (MFSA 2010-54)
vendor_redhat·2010-09-07·CVSS 8.8
CVE-2010-2760 [HIGH] Mozilla Dangling pointer vulnerability in nsTreeSelection (MFSA 2010-54)
Mozilla Dangling pointer vulnerability in nsTreeSelection (MFSA 2010-54)
Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via vectors involving a XUL tree selection, related to a "dangling pointer vulnerability." NOTE: this issue exists because of an incomplete fix for CVE-2010-2753.
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2010-07-26·CVSS 4.3
CVE-2010-0654 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Several flaws were discovered in the browser engine of Thunderbird. If a
user were tricked into viewing malicious content, a remote attacker could
use this to crash Thunderbird or possibly run arbitrary code as the user
invoking the program. (CVE-2010-1211, CVE-2010-1212)
An integer overflow was discovered in how Thunderbird processed CSS values.
An attacker could exploit this to crash Thunderbird or possibly run
arbitrary code as the user invoking the program. (CVE-2010-2752)
An integer overflow was discovered in how Thunderbird interpreted the XUL
element. If a user were tricked into viewing malicious content, a remote
attacker could use this to crash Thunderbird or possibly run arbitrary code
as the user invoking the program. (CVE-2010-2753)
Aki He
Ubuntu
Firefox and Xulrunner vulnerability
vendor_ubuntu·2010-07-26·CVSS 8.8
CVE-2010-2755 [HIGH] Firefox and Xulrunner vulnerability
Title: Firefox and Xulrunner vulnerability
Summary: Firefox could be made to run programs as your login if it opened a
specially crafted file or website.
USN-957-1 fixed vulnerabilities in Firefox and Xulrunner. Daniel Holbert
discovered that the fix for CVE-2010-1214 introduced a regression which did
not properly initialize a plugin pointer. If a user were tricked into
viewing a malicious site, a remote attacker could use this to crash the
browser or run arbitrary code as the user invoking the program.
(CVE-2010-2755)
This update fixes the problem.
Original advisory details:
Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious site, a remote attacker could use
this to crash the browser or possibly run arbitrary code as the us
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2010-07-23·CVSS 9.8
CVE-2008-5913 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox could be made to run programs as your login if it opened a
specially crafted file or website.
USN-930-1 fixed vulnerabilities in Firefox and Xulrunner. This update
provides the corresponding updates for Ubuntu 9.04 and 9.10, along with
additional updates affecting Firefox 3.6.6.
Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious site, a remote attacker could use
this to crash the browser or possibly run arbitrary code as the user
invoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,
CVE-2010-1212)
An integer overflow was discovered in how Firefox processed plugin
parameters. An attacker could exploit this to crash the browser or possibly
run arbitrary
Ubuntu
ant, apturl, Epiphany, gluezilla, gnome-python-extras, liferea, mozvoikko, OpenJDK, packagekit, ubufox, webfav, yelp update
vendor_ubuntu·2010-07-23·CVSS 10.0
[CRITICAL] ant, apturl, Epiphany, gluezilla, gnome-python-extras, liferea, mozvoikko, OpenJDK, packagekit, ubufox, webfav, yelp update
Title: ant, apturl, Epiphany, gluezilla, gnome-python-extras, liferea, mozvoikko, OpenJDK, packagekit, ubufox, webfav, yelp update
Summary: This update is for use with the new Xulrunner provided in USN-930-4.
USN-930-4 fixed vulnerabilities in Firefox and Xulrunner on Ubuntu 9.04 and
9.10. This update provides updated packages for use with Firefox 3.6 and
Xulrunner 1.9.2.
Original advisory details:
If was discovered that Firefox could be made to access freed memory. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS. (CVE-2010-1121)
Several flaws were discovered in the browser engine of Firefox. If a
user
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2010-07-23·CVSS 9.8
CVE-2010-1208 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox could be made to run programs as your login if it opened a
specially crafted file or website.
Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious site, a remote attacker could use
this to crash the browser or possibly run arbitrary code as the user
invoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,
CVE-2010-1212)
An integer overflow was discovered in how Firefox processed plugin
parameters. An attacker could exploit this to crash the browser or possibly
run arbitrary code as the user invoking the program. (CVE-2010-1214)
A flaw was discovered in the Firefox JavaScript engine. If a user were
tricked into viewing a malicious site, a remote attacker co
Red Hat
Mozilla nsTreeSelection dangling pointer remote code execution vulnerability
vendor_redhat·2010-07-20·CVSS 8.8
CVE-2010-2753 [HIGH] Mozilla nsTreeSelection dangling pointer remote code execution vulnerability
Mozilla nsTreeSelection dangling pointer remote code execution vulnerability
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free.
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-m5jc-6mwc-7vc7: Integer overflow in Mozilla Firefox 3
ghsa_unreviewed·2022-05-17
CVE-2010-2753 [HIGH] CWE-190 GHSA-m5jc-6mwc-7vc7: Integer overflow in Mozilla Firefox 3
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free.
GHSA
GHSA-vfwv-gjcf-p528: Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2010-2760 [HIGH] GHSA-vfwv-gjcf-p528: Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3
Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via vectors involving a XUL tree selection, related to a "dangling pointer vulnerability." NOTE: this issue exists because of an incomplete fix for CVE-2010-2753.
Suricata
ET WEB_CLIENT Mozilla Firefox nsTreeSelection Element invalidateSelection Remote Code Execution Attempt
suricata·2011-06-30
CVE-2010-2753 ET WEB_CLIENT Mozilla Firefox nsTreeSelection Element invalidateSelection Remote Code Execution Attempt
ET WEB_CLIENT Mozilla Firefox nsTreeSelection Element invalidateSelection Remote Code Execution Attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Mozilla Firefox nsTreeSelection Element invalidateSelection Remote Code Execution Attempt"; flow:established,to_client; file.data; content:"document.getElementById(|27|treeset|27|)"; fast_pattern; nocase; content:"view.selection"; nocase; distance:0; content:"invalidateRange"; nocase; distance:0; reference:bid,41853; reference:cve,2010-2753; classtype:attempted-user; sid:2013144; rev:3; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2011_06_30, cve CVE_2010_2753, deployment Perimeter, confidence Medium, signature_severity Major, tag Web_Client_
No public exploits indexed.
Bugzilla
CVE-2011-2753 SquirrelMail: CSRF in the empty trash feature and in Index Order page
bugzilla·2011-07-18·CVSS 4.3
CVE-2011-2753 [MEDIUM] CVE-2011-2753 SquirrelMail: CSRF in the empty trash feature and in Index Order page
CVE-2011-2753 SquirrelMail: CSRF in the empty trash feature and in Index Order page
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-2753 to
the following vulnerability:
Multiple cross-site request forgery (CSRF) vulnerabilities in
SquirrelMail 1.4.21 and earlier allow remote attackers to hijack the
authentication of unspecified victims via vectors involving (1) the
empty trash implementation and (2) the Index Order (aka options_order)
page, a different issue than CVE-2010-4555.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2753
[2] http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=revision&revision=14119
[3] https://bugzilla.redhat.com/show_bug.cgi?id=720694
Upstream patch (subpart of [3], relevant to options order and empty
Bugzilla
CVE-2010-4555 SquirrelMail: Multiple XSS flaws
bugzilla·2011-07-12·CVSS 4.3
CVE-2010-4555 [MEDIUM] CVE-2010-4555 SquirrelMail: Multiple XSS flaws
CVE-2010-4555 SquirrelMail: Multiple XSS flaws
Multiple cross-site scripting (XSS) flaws were found in the SquirrelMail webmail client:
* XSS flaws in generic options inputs,
* XSS flaw in the SquirrelSpell plug-in,
* XSS flaw in the Index Order page.
Also protection against Cross-site Request Forgery (CSRF) flaws has been added
to the empty trash feature and to the Index Order page.
The CSRF flaws got a dedicated CVE identifier of CVE-2011-2753. For further information have a look at:
[1] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2753
Upstream advisory:
[2] http://www.squirrelmail.org/security/issue/2011-07-11
Relevant upstream patch:
[3] http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=revision&revision=14119
Discussion:
These issues affect the versions
Bugzilla
CVE-2010-2760 Mozilla Dangling pointer vulnerability in nsTreeSelection (MFSA 2010-54)
bugzilla·2010-09-03·CVSS 8.8
CVE-2010-2760 [HIGH] CVE-2010-2760 Mozilla Dangling pointer vulnerability in nsTreeSelection (MFSA 2010-54)
CVE-2010-2760 Mozilla Dangling pointer vulnerability in nsTreeSelection (MFSA 2010-54)
Security researcher regenrecht reported via TippingPoint's Zero Day
Initiative that there was a remaining dangling pointer issue leftover from
the fix to CVE-2010-2753. Under certain circumstances one of the pointers
held by a XUL tree selection could be freed and then later reused,
potentially resulting in the execution of attacker-controlled memory.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2010/mfsa2010-54.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0682 https://rhn.redhat.com/errata/RHSA-2010-0682.html
---
This issue has been addressed in following products:
Red Hat Enterpri
Bugzilla
CVE-2010-2753 Mozilla nsTreeSelection dangling pointer remote code execution vulnerability
bugzilla·2010-07-16·CVSS 8.8
CVE-2010-2753 [HIGH] CVE-2010-2753 Mozilla nsTreeSelection dangling pointer remote code execution vulnerability
CVE-2010-2753 Mozilla nsTreeSelection dangling pointer remote code execution vulnerability
Security researcher regenrecht reported via TippingPoint's Zero Day
Initiative an integer overflow vulnerability in the implementation of the
XUL element's selection attribute. When the size of a new selection
is sufficiently large the integer used in calculating the length of the
selection can overflow, resulting in a bogus range being marked selected.
When adjustSelection is then called on the bogus range the range is deleted
leaving dangling references to the ranges which could be used by an
attacker to call into deleted memory and run arbitrary code on a victim's
computer.
Discussion:
This is now public: http://www.mozilla.org/security/announce/2010/mfsa2010-40.html
---
This issue has been a
CWE
Use After Free
mitre_cwe
CWE-416 Use After Free
CWE-416: Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Integrity. Impact: Modify Memory. The use of previously freed memory may corrupt valid data, if the memory area in question has been allocated and used properly elsewhere.
Scope: Availability. Impact: DoS: Crash, Exit, or Restart. If chunk consolidation occurs after the use of previously freed data, the process may crash
CWE
Integer Overflow or Wraparound
mitre_cwe
CWE-190 Integer Overflow or Wraparound
CWE-190: Integer Overflow or Wraparound
The product performs a calculation that can
produce an integer overflow or wraparound when the logic
assumes that the resulting value will always be larger than
the original value. This occurs when an integer value is
incremented to a value that is too large to store in the
associated representation. When this occurs, the value may
become a very small or negative number.
Modes of Introduction:
Phase: Implementation
Note: This weakness may become security critical when determining the offset or size in behaviors such as memory allocation, copying, and concatenation.
Common Consequences:
Scope: Availability. Impact: DoS: Crash, Exit, or Restart, DoS: Resource Consumption (Memory), DoS: Instability. This weakness can generally lead to undefined behav
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00002.htmlhttp://www.mozilla.org/security/announce/2010/mfsa2010-40.htmlhttp://www.securityfocus.com/archive/1/512510http://www.securityfocus.com/bid/41853http://www.zerodayinitiative.com/advisories/ZDI-10-131/https://bugzilla.mozilla.org/show_bug.cgi?id=571106https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10958http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00002.htmlhttp://www.mozilla.org/security/announce/2010/mfsa2010-40.htmlhttp://www.securityfocus.com/archive/1/512510http://www.securityfocus.com/bid/41853http://www.zerodayinitiative.com/advisories/ZDI-10-131/https://bugzilla.mozilla.org/show_bug.cgi?id=571106https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10958
2010-07-30
Published