CVE-2010-3171
published 2010-09-15CVE-2010-3171: The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random number…
PriorityP431medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EXPLOIT
EPSS
4.46%
90.2th percentile
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random number generator that is seeded only once per document object, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack." NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-5913.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 5.0.2 | — |
| apple | safari | <= 4.1.2 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv4.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h84m-77j2-99hq: The JavaScript implementation in WebKit in Apple Safari before 5
ghsa_unreviewed·2022-05-17·CVSS 4.9
CVE-2010-3804 [MEDIUM] GHSA-h84m-77j2-99hq: The JavaScript implementation in WebKit in Apple Safari before 5
The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, uses a weak algorithm for generating values of random numbers, which makes it easier for remote attackers to track a user by predicting a value, a related issue to CVE-2008-5913 and CVE-2010-3171.
GHSA
GHSA-hmj5-pvfm-pffx: The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2010-3399 [MEDIUM] GHSA-hmj5-pvfm-pffx: The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3
The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a context pointer in conjunction with its successor pointer for seeding of a random number generator, which makes it easier for remote attackers to guess the seed value via a brute-force attack, a different vulnerability than CVE-2010-3171.
GHSA
GHSA-v4fq-jrv5-w6jf: The Math
ghsa_unreviewed·2022-05-17·CVSS 4.9
CVE-2010-3171 [MEDIUM] GHSA-v4fq-jrv5-w6jf: The Math
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random number generator that is seeded only once per document object, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack." NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-5913.
OSV
CVE-2010-3804: The JavaScript implementation in WebKit in Apple Safari before 5
osv·2010-11-22·CVSS 4.9
CVE-2010-3804 [MEDIUM] CVE-2010-3804: The JavaScript implementation in WebKit in Apple Safari before 5
The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, uses a weak algorithm for generating values of random numbers, which makes it easier for remote attackers to track a user by predicting a value, a related issue to CVE-2008-5913 and CVE-2010-3171.
No detection rules found.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2010-09/0117.htmlhttp://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefoxhttp://secunia.com/advisories/42867http://www.securityfocus.com/bid/43222http://www.trusteer.com/sites/default/files/Cross_domain_Math_Random_leakage_in_FF_3.6.4-3.6.8.pdfhttp://www.vupen.com/english/advisories/2011/0061https://bugzilla.mozilla.org/show_bug.cgi?id=577512https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7370http://archives.neohapsis.com/archives/bugtraq/2010-09/0117.htmlhttp://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefoxhttp://secunia.com/advisories/42867http://www.securityfocus.com/bid/43222http://www.trusteer.com/sites/default/files/Cross_domain_Math_Random_leakage_in_FF_3.6.4-3.6.8.pdfhttp://www.vupen.com/english/advisories/2011/0061https://bugzilla.mozilla.org/show_bug.cgi?id=577512https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7370
2010-09-15
Published