CVE-2010-3774Improper Input Validation in Mozilla Firefox

Severity
4.3MEDIUMNVD
EPSS
1.0%
top 22.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10
Latest updateMay 17

Description

The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil.h in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle (1) about:neterror and (2) about:certerror pages, which allows remote attackers to spoof the location bar via a crafted web site.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDmozilla/firefox3.5.15+113
NVDmozilla/seamonkey2.0.10+43

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g9p5-q9ww-v8w9: The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil2022-05-17
CVEList
CVE-2010-3774: The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil2010-12-10

📋Vendor Advisories

2
Ubuntu
Firefox and Xulrunner vulnerabilities2010-12-09
Red Hat
Mozilla location bar SSL spoofing using network error page (MFSA 2010-83)2010-12-09

💬Community

1
Bugzilla
CVE-2010-3774 Mozilla location bar SSL spoofing using network error page (MFSA 2010-83)2010-12-06
CVE-2010-3774 — Improper Input Validation in Mozilla | cvebase