CVE-2010-2751: Low severity Mozilla Firefox vulnerability
The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocShell.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to spoof the SSL security status of a document via vectors involving multiple requests, a redirect, and the history.back and history.forward JavaScript functions.
Affected Software
Event History
Frequently Asked Questions
What are the affected versions for CVE-2010-2751?
CVE-2010-2751 affects Mozilla Firefox versions 3.5.x before 3.5.11, 3.6.x before 3.6.7, and SeaMonkey versions before 2.0.6.
What is the main risk associated with CVE-2010-2751?
The main risk is that remote attackers can spoof the SSL security status of a document.
How do I fix CVE-2010-2751?
To fix CVE-2010-2751, update your Mozilla Firefox or SeaMonkey to the latest versions that are not affected.
Is CVE-2010-2751 a critical vulnerability?
CVE-2010-2751 is considered a moderate risk vulnerability due to its ability to mislead users about the security status of web content.
What is the exploit method for CVE-2010-2751?
CVE-2010-2751 can be exploited through a series of multiple requests and redirects that manipulate SSL status.