Lucene search

K
mozillaMozilla FoundationMFSA2010-66
HistoryOct 19, 2010 - 12:00 a.m.

Use-after-free error in nsBarProp — Mozilla

2010-10-1900:00:00
Mozilla Foundation
www.mozilla.org
24

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.168

Percentile

96.1%

Security researcher Sergey Glazunov reported that it was possible to access the locationbar property of a window object after it had been closed. Since the closed window’s memory could have been subsequently reused by the system it was possible that an attempt to access the locationbar property could result in the execution of attacker-controlled memory.

Affected configurations

Vulners
Node
mozillafirefoxRange<3.5.14
OR
mozillafirefoxRange<3.6.11
OR
mozillaseamonkeyRange<2.0.9
OR
mozillathunderbirdRange<3.0.9
OR
mozillathunderbirdRange<3.1.5
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.168

Percentile

96.1%