CVE-2010-1213: Input Validation
The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not verify that content is valid JavaScript code, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted HTML document.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1213?
CVE-2010-1213 has a medium severity level due to its potential to allow attackers to bypass the Same Origin Policy.
How do I fix CVE-2010-1213?
To fix CVE-2010-1213, you should update Mozilla Firefox, Thunderbird, or SeaMonkey to the latest version available.
Which versions are affected by CVE-2010-1213?
CVE-2010-1213 affects Mozilla Firefox versions 3.5.x prior to 3.5.11, 3.6.x prior to 3.6.7, Thunderbird versions prior to 3.0.6 and 3.1.1, and SeaMonkey versions prior to 2.0.6.
What is CVE-2010-1213?
CVE-2010-1213 is a vulnerability in the importScripts method of web workers in certain versions of Mozilla applications, allowing JavaScript code validation bypass.
Can CVE-2010-1213 be exploited remotely?
Yes, CVE-2010-1213 can be exploited remotely, allowing attackers to execute arbitrary JavaScript code in the context of a user's session.