CVE-2010-3776
published 2010-12-10CVE-2010-3776: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before…
PriorityP339critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
8.67%
94.5th percentile
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Affected
218 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.5.15 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Xulrunner vulnerabilities
vendor_ubuntu·2011-04-30
CVE-2011-0077 Xulrunner vulnerabilities
Title: Xulrunner vulnerabilities
Summary: Multiple xulrunner-1.9.1 vulnerabilities
A large number of security issues were discovered in the Gecko rendering
engine. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: After a standard system update you need to restart any applications which
use Xulrunner to make all the necessary changes.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2010-12-09·CVSS 9.3
CVE-2010-3776 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it opened a
specially crafted website.
Jesse Ruderman, Andreas Gal, Nils, Brian Hackett, and Igor Bukanov
discovered several memory issues in the browser engine. An attacker could
exploit these to crash the browser or possibly run arbitrary code as the
user invoking the program. (CVE-2010-3776, CVE-2010-3777, CVE-2010-3778)
It was discovered that Firefox did not properly verify the about:blank
location elements when it was opened via window.open(). An attacker could
exploit this to run arbitrary code with chrome privileges. (CVE-2010-3771)
It was discovered that Firefox did not properly handle elements
when processing a XUL tree. If a user were tricked into opening a ma
Red Hat
Mozilla miscellaneous memory safety hazards (MFSA 2010-74)
vendor_redhat·2010-12-09·CVSS 9.3
CVE-2010-3776 [CRITICAL] Mozilla miscellaneous memory safety hazards (MFSA 2010-74)
Mozilla miscellaneous memory safety hazards (MFSA 2010-74)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Package: firefox (Red Hat Enterprise Linux Extended Update Support 4.8) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update Support 4.8) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 5.5) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update Support 5.5) - Affected
Package: firefox (Red Hat Enterprise Linux Extende
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2010-12-09·CVSS 9.3
CVE-2010-3777 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird could be made to crash or run programs as your login if it
opened a specially crafted file.
Jesse Ruderman, Andreas Gal, Nils, Brian Hackett, and Igor Bukanov
discovered several memory issues in the browser engine. An attacker could
exploit these to crash THunderbird or possibly run arbitrary code as the
user invoking the program. (CVE-2010-3776, CVE-2010-3777, CVE-2010-3778)
Marc Schoenefeld and Christoph Diehl discovered several problems when
handling downloadable fonts. The new OTS font sanitizing library was added
to mitigate these issues. (CVE-2010-3768)
Instructions: After a standard system update you need to restart Thunderbird to make
all the necessary changes.
GHSA
GHSA-wmch-5hcw-ch97: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-17
CVE-2010-3776 [HIGH] CWE-119 GHSA-wmch-5hcw-ch97: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052022.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052032.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052110.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052220.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052502.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052504.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00002.htmlhttp://secunia.com/advisories/42716http://secunia.com/advisories/42818http://support.avaya.com/css/P8/documents/100124650http://www.debian.org/security/2010/dsa-2132http://www.mandriva.com/security/advisories?name=MDVSA-2010:251http://www.mandriva.com/security/advisories?name=MDVSA-2010:258http://www.mozilla.org/security/announce/2010/mfsa2010-74.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0966.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0967.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0968.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0969.htmlhttp://www.securityfocus.com/bid/45347http://www.securitytracker.com/id?1024846http://www.securitytracker.com/id?1024848http://www.ubuntu.com/usn/USN-1019-1http://www.ubuntu.com/usn/USN-1020-1http://www.vupen.com/english/advisories/2011/0030https://bugzilla.mozilla.org/show_bug.cgi?id=468563https://bugzilla.mozilla.org/show_bug.cgi?id=569162https://bugzilla.mozilla.org/show_bug.cgi?id=571995https://bugzilla.mozilla.org/show_bug.cgi?id=599166https://bugzilla.mozilla.org/show_bug.cgi?id=601699https://bugzilla.mozilla.org/show_bug.cgi?id=604843https://bugzilla.mozilla.org/show_bug.cgi?id=605307https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12389http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052022.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052032.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052110.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052220.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052502.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052504.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00002.htmlhttp://secunia.com/advisories/42716http://secunia.com/advisories/42818http://support.avaya.com/css/P8/documents/100124650http://www.debian.org/security/2010/dsa-2132http://www.mandriva.com/security/advisories?name=MDVSA-2010:251http://www.mandriva.com/security/advisories?name=MDVSA-2010:258http://www.mozilla.org/security/announce/2010/mfsa2010-74.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0966.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0967.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0968.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0969.htmlhttp://www.securityfocus.com/bid/45347http://www.securitytracker.com/id?1024846http://www.securitytracker.com/id?1024848http://www.ubuntu.com/usn/USN-1019-1http://www.ubuntu.com/usn/USN-1020-1http://www.vupen.com/english/advisories/2011/0030https://bugzilla.mozilla.org/show_bug.cgi?id=468563https://bugzilla.mozilla.org/show_bug.cgi?id=569162https://bugzilla.mozilla.org/show_bug.cgi?id=571995https://bugzilla.mozilla.org/show_bug.cgi?id=599166https://bugzilla.mozilla.org/show_bug.cgi?id=601699https://bugzilla.mozilla.org/show_bug.cgi?id=604843https://bugzilla.mozilla.org/show_bug.cgi?id=605307https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12389
2010-12-10
Published