CVE-2010-0177: Critical severity Mozilla Firefox vulnerability
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plugins array while a reference to an array element is still active, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, related to a "dangling pointer vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0177?
CVE-2010-0177 is considered a critical vulnerability that can allow remote attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2010-0177?
To fix CVE-2010-0177, update your Mozilla Firefox or SeaMonkey to the latest version that is not affected by this vulnerability.
Which versions of Firefox are affected by CVE-2010-0177?
CVE-2010-0177 affects Mozilla Firefox versions before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2.
Can CVE-2010-0177 lead to data loss?
Yes, CVE-2010-0177 can potentially lead to data loss as it allows remote execution of arbitrary code.
Is there a workaround for CVE-2010-0177?
Disabling JavaScript may provide a temporary workaround for CVE-2010-0177, but upgrading to a secure version is strongly recommended.