CVE-2010-3774
published 2010-12-10CVE-2010-3774: The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil.h in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.64%
73.9th percentile
The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil.h in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle (1) about:neterror and (2) about:certerror pages, which allows remote attackers to spoof the location bar via a crafted web site.
Affected
158 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.5.15 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu9.3CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2010-12-09·CVSS 9.3
CVE-2010-3776 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it opened a
specially crafted website.
Jesse Ruderman, Andreas Gal, Nils, Brian Hackett, and Igor Bukanov
discovered several memory issues in the browser engine. An attacker could
exploit these to crash the browser or possibly run arbitrary code as the
user invoking the program. (CVE-2010-3776, CVE-2010-3777, CVE-2010-3778)
It was discovered that Firefox did not properly verify the about:blank
location elements when it was opened via window.open(). An attacker could
exploit this to run arbitrary code with chrome privileges. (CVE-2010-3771)
It was discovered that Firefox did not properly handle elements
when processing a XUL tree. If a user were tricked into opening a ma
Red Hat
Mozilla location bar SSL spoofing using network error page (MFSA 2010-83)
vendor_redhat·2010-12-09·CVSS 4.3
CVE-2010-3774 [MEDIUM] Mozilla location bar SSL spoofing using network error page (MFSA 2010-83)
Mozilla location bar SSL spoofing using network error page (MFSA 2010-83)
The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil.h in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle (1) about:neterror and (2) about:certerror pages, which allows remote attackers to spoof the location bar via a crafted web site.
Package: firefox (Red Hat Enterprise Linux Extended Update Support 4.8) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 5.5) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 6.0) - Affected
GHSA
GHSA-g9p5-q9ww-v8w9: The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil
ghsa_unreviewed·2022-05-17
CVE-2010-3774 [MEDIUM] CWE-20 GHSA-g9p5-q9ww-v8w9: The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil
The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil.h in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle (1) about:neterror and (2) about:certerror pages, which allows remote attackers to spoof the location bar via a crafted web site.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052022.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052032.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052502.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052504.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00002.htmlhttp://secunia.com/advisories/42716http://secunia.com/advisories/42818http://support.avaya.com/css/P8/documents/100124650http://www.mandriva.com/security/advisories?name=MDVSA-2010:251http://www.mozilla.org/security/announce/2010/mfsa2010-83.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0966.htmlhttp://www.securitytracker.com/id?1024850http://www.ubuntu.com/usn/USN-1019-1http://www.vupen.com/english/advisories/2011/0030https://bugzilla.mozilla.org/show_bug.cgi?id=602780https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12512http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052022.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052032.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052502.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052504.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00002.htmlhttp://secunia.com/advisories/42716http://secunia.com/advisories/42818http://support.avaya.com/css/P8/documents/100124650http://www.mandriva.com/security/advisories?name=MDVSA-2010:251http://www.mozilla.org/security/announce/2010/mfsa2010-83.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0966.htmlhttp://www.securitytracker.com/id?1024850http://www.ubuntu.com/usn/USN-1019-1http://www.vupen.com/english/advisories/2011/0030https://bugzilla.mozilla.org/show_bug.cgi?id=602780https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12512
2010-12-10
Published