CVE-2010-3767
published 2010-12-10CVE-2010-3767: Integer overflow in the NewIdArray function in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to…
critical9.3CVSS 3.1
AVNACMAuNCCICAC
Integer overflow in the NewIdArray function in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via a JavaScript array with many elements.
Affected
140 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.5.15 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2010-12-09·CVSS 9.3
CVE-2010-3776 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it opened a
specially crafted website.
Jesse Ruderman, Andreas Gal, Nils, Brian Hackett, and Igor Bukanov
discovered several memory issues in the browser engine. An attacker could
exploit these to crash the browser or possibly run arbitrary code as the
user invoking the program. (CVE-2010-3776, CVE-2010-3777, CVE-2010-3778)
It was discovered that Firefox did not properly verify the about:blank
location elements when it was opened via window.open(). An attacker could
exploit this to run arbitrary code with chrome privileges. (CVE-2010-3771)
It was discovered that Firefox did not properly handle elements
when processing a XUL tree. If a user were tricked into opening a ma
Red Hat
Mozilla integer overflow vulnerability in NewIdArray (MFSA 2010-81)
vendor_redhat·2010-12-09·CVSS 9.3
CVE-2010-3767 [CRITICAL] CWE-190 Mozilla integer overflow vulnerability in NewIdArray (MFSA 2010-81)
Mozilla integer overflow vulnerability in NewIdArray (MFSA 2010-81)
Integer overflow in the NewIdArray function in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via a JavaScript array with many elements.
Package: firefox (Red Hat Enterprise Linux Extended Update Support 4.8) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 5.5) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 6.0) - Affected
Red Hat
OpenLDAP: Doesn't properly handle NULL character in subject Common Name
vendor_redhat·2009-08-10·CVSS 5.9
CVE-2009-3767 [MEDIUM] OpenLDAP: Doesn't properly handle NULL character in subject Common Name
OpenLDAP: Doesn't properly handle NULL character in subject Common Name
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Statement: This issue was addressed in the openldap packages as shipped with Red Hat Enterprise Linux 5 and 4 via: https://rhn.redhat.com/errata/RHSA-2010-0198.html and https://rhn.redhat.com/errata/RHSA-2010-0543.html respectively.
The Red Hat Security Response Team has rated this issue as having moderate security imp
GHSA
GHSA-g65j-65qf-2mcj: Integer overflow in the NewIdArray function in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-17
CVE-2010-3767 [HIGH] GHSA-g65j-65qf-2mcj: Integer overflow in the NewIdArray function in Mozilla Firefox before 3
Integer overflow in the NewIdArray function in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via a JavaScript array with many elements.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052022.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052032.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052502.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052504.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00002.htmlhttp://secunia.com/advisories/42716http://secunia.com/advisories/42818http://support.avaya.com/css/P8/documents/100124650http://www.debian.org/security/2010/dsa-2132http://www.mandriva.com/security/advisories?name=MDVSA-2010:251http://www.mozilla.org/security/announce/2010/mfsa2010-81.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0966.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0967.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0968.htmlhttp://www.securitytracker.com/id?1024848http://www.ubuntu.com/usn/USN-1019-1http://www.vupen.com/english/advisories/2011/0030https://bugzilla.mozilla.org/show_bug.cgi?id=599468https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12610http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052022.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052032.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052502.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052504.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00002.htmlhttp://secunia.com/advisories/42716http://secunia.com/advisories/42818http://support.avaya.com/css/P8/documents/100124650http://www.debian.org/security/2010/dsa-2132http://www.mandriva.com/security/advisories?name=MDVSA-2010:251http://www.mozilla.org/security/announce/2010/mfsa2010-81.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0966.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0967.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0968.htmlhttp://www.securitytracker.com/id?1024848http://www.ubuntu.com/usn/USN-1019-1http://www.vupen.com/english/advisories/2011/0030https://bugzilla.mozilla.org/show_bug.cgi?id=599468https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12610
2010-12-10
Published