CVE-2010-0176: Critical severity Mozilla Firefox vulnerability
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to deleted elements, related to a "dangling pointer vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0176?
The severity of CVE-2010-0176 is classified as high due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2010-0176?
To fix CVE-2010-0176, upgrade to Firefox version 3.0.19, 3.5.9, 3.6.2 or later, or upgrade Thunderbird and SeaMonkey to their respective secure updates.
Which applications are affected by CVE-2010-0176?
CVE-2010-0176 affects Mozilla Firefox versions prior to 3.0.19, 3.5.x before 3.5.9, 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4.
What types of attacks are enabled by CVE-2010-0176?
CVE-2010-0176 can enable remote attackers to exploit the vulnerability through unspecified vectors for executing arbitrary code.
When was CVE-2010-0176 introduced?
CVE-2010-0176 was introduced in earlier versions of Mozilla applications and addressed in updates released in 2010.