CVE-2010-3167
published 2010-09-09CVE-2010-3167: The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before…
PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.53%
93.0th percentile
The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle node removal in XUL trees, which allows remote attackers to execute arbitrary code via vectors involving access to deleted memory, related to a "dangling pointer vulnerability."
Affected
197 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.5.11 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and Xulrunner regression
vendor_ubuntu·2010-09-16·CVSS 9.3
[CRITICAL] Firefox and Xulrunner regression
Title: Firefox and Xulrunner regression
Summary: This update provides stability updates for Firefox and Xulrunner.
USN-975-1 fixed vulnerabilities in Firefox and Xulrunner. Some users
reported stability problems under certain circumstances. This update fixes
the problem.
We apologize for the inconvenience.
Original advisory details:
Several dangling pointer vulnerabilities were discovered in Firefox. An
attacker could exploit this to crash the browser or possibly run arbitrary
code as the user invoking the program. (CVE-2010-2760, CVE-2010-2767,
CVE-2010-3167)
Blake Kaplan and Michal Zalewski discovered several weaknesses in the
XPCSafeJSObjectWrapper (SJOW) security wrapper. If a user were tricked into
viewing a malicious site, a remote attacker could use this to run arbitrary
JavaS
Ubuntu
Thunderbird regression
vendor_ubuntu·2010-09-16·CVSS 9.3
[CRITICAL] Thunderbird regression
Title: Thunderbird regression
Summary: This update provides stability updates for Thunderbird.
USN-978-1 fixed vulnerabilities in Thunderbird. Some users reported
stability problems under certain circumstances. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Several dangling pointer vulnerabilities were discovered in Thunderbird. An
attacker could exploit this to crash Thunderbird or possibly run arbitrary
code as the user invoking the program. (CVE-2010-2760, CVE-2010-2767,
CVE-2010-3167)
It was discovered that the XPCSafeJSObjectWrapper (SJOW) security wrapper
did not always honor the same-origin policy. If JavaScript was enabled, an
attacker could exploit this to run untrusted JavaScript from other domains.
(CVE-2010-2763)
Matt Haggar
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2010-09-08·CVSS 9.3
CVE-2010-2763 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird could be made to crash or possibly run programs as your login
if it opened a specially crafted file or website.
Several dangling pointer vulnerabilities were discovered in Thunderbird. An
attacker could exploit this to crash Thunderbird or possibly run arbitrary
code as the user invoking the program. (CVE-2010-2760, CVE-2010-2767,
CVE-2010-3167)
It was discovered that the XPCSafeJSObjectWrapper (SJOW) security wrapper
did not always honor the same-origin policy. If JavaScript was enabled, an
attacker could exploit this to run untrusted JavaScript from other domains.
(CVE-2010-2763)
Matt Haggard discovered that Thunderbird did not honor same-origin policy
when processing the statusText property of an XMLHttpRequest object. If a
use
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2010-09-08·CVSS 9.3
CVE-2010-2764 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox could be made to crash or possibly run programs as your login if it
opened a specially crafted file or website.
Several dangling pointer vulnerabilities were discovered in Firefox. An
attacker could exploit this to crash the browser or possibly run arbitrary
code as the user invoking the program. (CVE-2010-2760, CVE-2010-2767,
CVE-2010-3167)
Blake Kaplan and Michal Zalewski discovered several weaknesses in the
XPCSafeJSObjectWrapper (SJOW) security wrapper. If a user were tricked into
viewing a malicious site, a remote attacker could use this to run arbitrary
JavaScript with chrome privileges. (CVE-2010-2762)
Matt Haggard discovered that Firefox did not honor same-origin policy when
processing the statusText property of an X
Red Hat
Mozilla Dangling pointer vulnerability in nsTreeContentView (MFSA 2010-56)
vendor_redhat·2010-09-07·CVSS 9.3
CVE-2010-3167 [CRITICAL] Mozilla Dangling pointer vulnerability in nsTreeContentView (MFSA 2010-56)
Mozilla Dangling pointer vulnerability in nsTreeContentView (MFSA 2010-56)
The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle node removal in XUL trees, which allows remote attackers to execute arbitrary code via vectors involving access to deleted memory, related to a "dangling pointer vulnerability."
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-996j-6q9j-r4xp: The nsTreeContentView function in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-17
CVE-2010-3167 [HIGH] CWE-119 GHSA-996j-6q9j-r4xp: The nsTreeContentView function in Mozilla Firefox before 3
The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle node removal in XUL trees, which allows remote attackers to execute arbitrary code via vectors involving access to deleted memory, related to a "dangling pointer vulnerability."
No detection rules found.
No public exploits indexed.
http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefoxhttp://lists.fedoraproject.org/pipermail/package-announce/2010-September/047282.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-10/msg00002.htmlhttp://secunia.com/advisories/42867http://support.avaya.com/css/P8/documents/100110210http://support.avaya.com/css/P8/documents/100112690http://www.debian.org/security/2010/dsa-2106http://www.mandriva.com/security/advisories?name=MDVSA-2010:173http://www.mozilla.org/security/announce/2010/mfsa2010-56.htmlhttp://www.securityfocus.com/bid/43097http://www.vupen.com/english/advisories/2010/2323http://www.vupen.com/english/advisories/2011/0061http://www.zerodayinitiative.com/advisories/ZDI-10-171/https://bugzilla.mozilla.org/show_bug.cgi?id=576070https://exchange.xforce.ibmcloud.com/vulnerabilities/61661https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12136http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefoxhttp://lists.fedoraproject.org/pipermail/package-announce/2010-September/047282.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-10/msg00002.htmlhttp://secunia.com/advisories/42867http://support.avaya.com/css/P8/documents/100110210http://support.avaya.com/css/P8/documents/100112690http://www.debian.org/security/2010/dsa-2106http://www.mandriva.com/security/advisories?name=MDVSA-2010:173http://www.mozilla.org/security/announce/2010/mfsa2010-56.htmlhttp://www.securityfocus.com/bid/43097http://www.vupen.com/english/advisories/2010/2323http://www.vupen.com/english/advisories/2011/0061http://www.zerodayinitiative.com/advisories/ZDI-10-171/https://bugzilla.mozilla.org/show_bug.cgi?id=576070https://exchange.xforce.ibmcloud.com/vulnerabilities/61661https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12136
2010-09-09
Published