First published: Sun Feb 21 2010(Updated: )
The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | =3.5.3 | |
Mozilla Firefox | =3.0.7 | |
Mozilla Firefox | =3.0.9 | |
Mozilla Firefox | =3.5.6 | |
Mozilla Firefox | =3.0.8 | |
Mozilla Firefox | =3.5 | |
Mozilla Firefox | =3.5.5 | |
Mozilla Firefox | =3.0.4 | |
Mozilla Firefox | =3.5.4 | |
Mozilla Firefox | =3.5.7 | |
Mozilla Firefox | =3.0.5 | |
Mozilla Firefox | =3.5.1 | |
Mozilla Firefox | =3.0.14 | |
Mozilla Firefox | =3.5.2 | |
Mozilla Firefox | =3.0.10 | |
Mozilla Firefox | =3.0.12 | |
Mozilla Firefox | =3.0.3 | |
Mozilla Firefox | =3.0.6 | |
Mozilla Firefox | =3.0.15 | |
Mozilla Firefox | =3.0 | |
Mozilla Firefox | =3.0.1 | |
Mozilla Firefox | <=3.0.17 | |
Mozilla Firefox | =3.0.2 | |
Mozilla Firefox | =3.0.13 | |
Mozilla Firefox | =3.0.16 | |
Mozilla Firefox | =3.0.11 | |
Mozilla SeaMonkey | =1.1.10 | |
Mozilla SeaMonkey | =1.0.3 | |
Mozilla SeaMonkey | =1.1.8 | |
Mozilla SeaMonkey | =1.0.1 | |
Mozilla SeaMonkey | =1.1.7 | |
Mozilla SeaMonkey | =1.0.6 | |
Mozilla SeaMonkey | =1.0.9 | |
Mozilla SeaMonkey | =1.1.3 | |
Mozilla SeaMonkey | =1.0 | |
Mozilla SeaMonkey | =1.1.17 | |
Mozilla SeaMonkey | =2.0-alpha_2 | |
Mozilla SeaMonkey | =1.1.5 | |
Mozilla SeaMonkey | =1.0.7 | |
Mozilla SeaMonkey | =1.0-beta | |
Mozilla SeaMonkey | =1.1-alpha | |
Mozilla SeaMonkey | =2.0-rc2 | |
Mozilla SeaMonkey | =2.0-alpha_3 | |
Mozilla SeaMonkey | =1.0-alpha | |
Mozilla SeaMonkey | <=2.0.2 | |
Mozilla SeaMonkey | =1.1.12 | |
Mozilla SeaMonkey | =1.1 | |
Mozilla SeaMonkey | =1.1.14 | |
Mozilla SeaMonkey | =1.1.2 | |
Mozilla SeaMonkey | =2.0-beta_2 | |
Mozilla SeaMonkey | =1.0.2 | |
Mozilla SeaMonkey | =1.0.8 | |
Mozilla SeaMonkey | =1.1.11 | |
Mozilla SeaMonkey | =2.0-alpha_1 | |
Mozilla SeaMonkey | =1.1-beta | |
Mozilla SeaMonkey | =1.1.1 | |
Mozilla SeaMonkey | =2.0.1 | |
Mozilla SeaMonkey | =1.0.5 | |
Mozilla SeaMonkey | =1.1.15 | |
Mozilla SeaMonkey | =1.1.6 | |
Mozilla SeaMonkey | =1.1.16 | |
Mozilla SeaMonkey | =2.0-beta_1 | |
Mozilla SeaMonkey | =2.0-rc1 | |
Mozilla SeaMonkey | =1.0.4 | |
Mozilla SeaMonkey | =1.1.9 | |
Mozilla SeaMonkey | =1.1.13 | |
Mozilla SeaMonkey | =2.0 | |
Mozilla SeaMonkey | =1.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0160 has been classified as a low severity vulnerability that can lead to denial of service through heap memory corruption affecting Firefox and SeaMonkey.
To fix CVE-2010-0160, users should upgrade to Firefox version 3.0.18 or later or SeaMonkey version 2.0.3 or later.
CVE-2010-0160 affects Mozilla Firefox versions 3.0.x before 3.0.18 and 3.5.x before 3.5.8, as well as SeaMonkey versions before 2.0.3.
CVE-2010-0160 allows remote attackers to cause a denial of service through an exploit that targets the Web Worker functionality.
CVE-2010-0160 specifically impacts Mozilla Firefox and SeaMonkey browsers, particularly older versions prior to their respective patches.