CVE-2010-3177Cross-site Scripting in Mozilla Firefox

Severity
4.3MEDIUMNVD
EPSS
0.7%
top 27.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Gopher parser in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, and SeaMonkey before 2.0.9, allow remote attackers to inject arbitrary web script or HTML via a crafted name of a (1) file or (2) directory on a Gopher server.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDmozilla/firefox3.5.13+91
NVDmozilla/seamonkey2.0.8+41

🔴Vulnerability Details

2
GHSA
GHSA-hvcx-xp6v-2hrj: Multiple cross-site scripting (XSS) vulnerabilities in the Gopher parser in Mozilla Firefox before 32022-05-17
CVEList
CVE-2010-3177: Multiple cross-site scripting (XSS) vulnerabilities in the Gopher parser in Mozilla Firefox before 32010-10-21

📋Vendor Advisories

2
Ubuntu
Firefox and Xulrunner vulnerabilities2010-10-20
Red Hat
Mozilla XSS in gopher parser when parsing hrefs2010-10-19

💬Community

1
Bugzilla
CVE-2010-3177 Mozilla XSS in gopher parser when parsing hrefs2010-10-12
CVE-2010-3177 — Cross-site Scripting in Mozilla Firefox | cvebase