CVE-2010-3771Mozilla Firefox vulnerability

6 documents6 sources
Severity
6.8MEDIUMNVD
EPSS
2.2%
top 15.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10
Latest updateMay 17

Description

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to redirection to a chrome: URI.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages2 packages

NVDmozilla/firefox3.5.15+113
NVDmozilla/seamonkey2.0.10+43

🔴Vulnerability Details

2
GHSA
GHSA-w2c5-5mgc-qjcf: Mozilla Firefox before 32022-05-17
CVEList
CVE-2010-3771: Mozilla Firefox before 32010-12-10

📋Vendor Advisories

2
Ubuntu
Firefox and Xulrunner vulnerabilities2010-12-09
Red Hat
Mozilla Chrome privilege escalation with window.open and <isindex> element (MFSA 2010-76)2010-12-09

💬Community

1
Bugzilla
CVE-2010-3771 Mozilla Chrome privilege escalation with window.open and <isindex> element (MFSA 2010-76)2010-12-06
CVE-2010-3771 — Mozilla Firefox vulnerability | cvebase