CVE-2010-2760: Use After Free
Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via vectors involving a XUL tree selection, related to a "dangling pointer vulnerability." NOTE: this issue exists because of an incomplete fix for CVE-2010-2753.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2760?
The severity of CVE-2010-2760 is classified as critical due to the potential for remote code execution.
How do I fix CVE-2010-2760?
To mitigate CVE-2010-2760, update Mozilla Firefox, Thunderbird, or SeaMonkey to the latest version that includes the security patches.
Which versions of Firefox are affected by CVE-2010-2760?
CVE-2010-2760 affects Firefox versions before 3.5.12 and 3.6.x before 3.6.9.
Are Thunderbird and SeaMonkey also affected by CVE-2010-2760?
Yes, CVE-2010-2760 impacts Thunderbird versions prior to 3.0.7 and 3.1.x before 3.1.3, as well as SeaMonkey versions before 2.0.7.
What causes the vulnerability CVE-2010-2760?
CVE-2010-2760 is caused by a use-after-free vulnerability in the nsTreeSelection function, which can be exploited via XUL tree selections.