CVE-2010-1210: Input Validation
intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 inserts a U+FFFD sequence into text in certain circumstances involving undefined positions, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted 8-bit text.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1210?
CVE-2010-1210 has been classified as a high severity vulnerability due to its potential for facilitating cross-site scripting (XSS) attacks.
How do I fix CVE-2010-1210?
To address CVE-2010-1210, users should update to Mozilla Firefox version 3.6.7 or later and Thunderbird version 3.1.1 or later.
What software is affected by CVE-2010-1210?
CVE-2010-1210 affects Mozilla Firefox versions prior to 3.6.7 and Thunderbird versions prior to 3.1.1.
What type of attack does CVE-2010-1210 enable?
CVE-2010-1210 enables attackers to conduct cross-site scripting (XSS) attacks via crafted input.
When was CVE-2010-1210 published?
CVE-2010-1210 was published on March 31, 2010.