Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-3765
HistoryOct 27, 2010 - 12:00 a.m.

CVE-2010-3765

2010-10-2700:00:00
ubuntu.com
ubuntu.com
27

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.969

Percentile

99.8%

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird
3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before
2.0.10, when JavaScript is enabled, allows remote attackers to execute
arbitrary code via vectors related to
nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect
index tracking, and the creation of multiple frames, which triggers memory
corruption, as exploited in the wild in October 2010 by the Belmoo malware.

Notes

Author Note
jdstrand 0-day exploit in wild for Windows. Presumed that other platforms will follow soon. It is unclear if compiler and kernel protections will protect against this, and upstream considers this extremely serious.
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchfirefox<Β 3.6.12+build1+nobinonly-0ubuntu0.10.04.1UNKNOWN
ubuntu10.10noarchfirefox<Β 3.6.12+build1+nobinonly-0ubuntu0.10.10.1UNKNOWN
ubuntu8.04noarchfirefox-3.0<Β 3.6.12+build1+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu9.10noarchfirefox-3.5<Β 3.6.12+build1+nobinonly-0ubuntu0.9.10.1UNKNOWN
ubuntu8.04noarchseamonkey<Β 2.0.10+build1+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu9.10noarchseamonkey<Β 2.0.10+build1+nobinonly-0ubuntu0.9.10.1UNKNOWN
ubuntu10.04noarchseamonkey<Β 2.0.10+build1+nobinonly-0ubuntu0.10.04.1UNKNOWN
ubuntu10.10noarchseamonkey<Β 2.0.10+build1+nobinonly-0ubuntu0.10.10.1UNKNOWN
ubuntu8.04noarchthunderbird<Β 2.0.0.24+build1+nobinonly-0ubuntu0.8.04.2UNKNOWN
ubuntu9.10noarchthunderbird<Β 2.0.0.24+build1+nobinonly-0ubuntu0.9.10.3UNKNOWN
Rows per page:
1-10 of 161

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.969

Percentile

99.8%