CVE-2010-1196: Buffer Overflow
Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a DOM node with a long text value that triggers a heap-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1196?
CVE-2010-1196 is considered a high severity vulnerability that allows remote attackers to execute arbitrary code.
How do I fix CVE-2010-1196?
To fix CVE-2010-1196, update to Firefox version 3.5.10 or later, 3.6.4 or later, Thunderbird version 3.0.5 or later, or SeaMonkey version 2.0.5 or later.
Which software versions are affected by CVE-2010-1196?
CVE-2010-1196 affects Mozilla Firefox versions 3.5.1 to 3.5.9, versions 3.6 to 3.6.3, Thunderbird versions prior to 3.0.5, and SeaMonkey versions prior to 2.0.5.
What types of attacks can exploit CVE-2010-1196?
CVE-2010-1196 allows attackers to exploit an integer overflow vulnerability through crafted DOM nodes, potentially leading to arbitrary code execution.
Is there a workaround for CVE-2010-1196?
There is no known workaround for CVE-2010-1196 other than applying the appropriate software updates.