First published: Thu Sep 09 2010(Updated: )
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict read access to the statusText property of XMLHttpRequest objects, which allows remote attackers to discover the existence of intranet web servers via cross-origin requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | =3.6 | |
Mozilla Firefox | =3.6.2 | |
Mozilla Firefox | =3.6.3 | |
Mozilla Firefox | =3.6.4 | |
Mozilla Firefox | =3.6.6 | |
Mozilla Firefox | =3.6.7 | |
Mozilla Firefox | =3.6.8 | |
Mozilla SeaMonkey | <=2.0.6 | |
Mozilla SeaMonkey | =1.0 | |
Mozilla SeaMonkey | =1.0-alpha | |
Mozilla SeaMonkey | =1.0-beta | |
Mozilla SeaMonkey | =1.0.1 | |
Mozilla SeaMonkey | =1.0.2 | |
Mozilla SeaMonkey | =1.0.3 | |
Mozilla SeaMonkey | =1.0.4 | |
Mozilla SeaMonkey | =1.0.5 | |
Mozilla SeaMonkey | =1.0.6 | |
Mozilla SeaMonkey | =1.0.7 | |
Mozilla SeaMonkey | =1.0.8 | |
Mozilla SeaMonkey | =1.0.9 | |
Mozilla SeaMonkey | =1.1 | |
Mozilla SeaMonkey | =1.1-alpha | |
Mozilla SeaMonkey | =1.1-beta | |
Mozilla SeaMonkey | =1.1.1 | |
Mozilla SeaMonkey | =1.1.2 | |
Mozilla SeaMonkey | =1.1.3 | |
Mozilla SeaMonkey | =1.1.4 | |
Mozilla SeaMonkey | =1.1.5 | |
Mozilla SeaMonkey | =1.1.6 | |
Mozilla SeaMonkey | =1.1.7 | |
Mozilla SeaMonkey | =1.1.8 | |
Mozilla SeaMonkey | =1.1.9 | |
Mozilla SeaMonkey | =1.1.10 | |
Mozilla SeaMonkey | =1.1.11 | |
Mozilla SeaMonkey | =1.1.12 | |
Mozilla SeaMonkey | =1.1.13 | |
Mozilla SeaMonkey | =1.1.14 | |
Mozilla SeaMonkey | =1.1.15 | |
Mozilla SeaMonkey | =1.1.16 | |
Mozilla SeaMonkey | =1.1.17 | |
Mozilla SeaMonkey | =1.1.18 | |
Mozilla SeaMonkey | =1.1.19 | |
Mozilla SeaMonkey | =1.5.0.8 | |
Mozilla SeaMonkey | =1.5.0.9 | |
Mozilla SeaMonkey | =1.5.0.10 | |
Mozilla SeaMonkey | =2.0 | |
Mozilla SeaMonkey | =2.0-alpha_1 | |
Mozilla SeaMonkey | =2.0-alpha_2 | |
Mozilla SeaMonkey | =2.0-alpha_3 | |
Mozilla SeaMonkey | =2.0-beta_1 | |
Mozilla SeaMonkey | =2.0-beta_2 | |
Mozilla SeaMonkey | =2.0-rc1 | |
Mozilla SeaMonkey | =2.0-rc2 | |
Mozilla SeaMonkey | =2.0.1 | |
Mozilla SeaMonkey | =2.0.2 | |
Mozilla SeaMonkey | =2.0.3 | |
Mozilla SeaMonkey | =2.0.4 | |
Mozilla SeaMonkey | =2.0.5 | |
Mozilla SeaMonkey | =2.0a1pre | |
Mozilla Thunderbird | <=3.0.6 | |
Mozilla Thunderbird | =0.1 | |
Mozilla Thunderbird | =0.2 | |
Mozilla Thunderbird | =0.3 | |
Mozilla Thunderbird | =0.4 | |
Mozilla Thunderbird | =0.5 | |
Mozilla Thunderbird | =0.6 | |
Mozilla Thunderbird | =0.7 | |
Mozilla Thunderbird | =0.7.1 | |
Mozilla Thunderbird | =0.7.2 | |
Mozilla Thunderbird | =0.7.3 | |
Mozilla Thunderbird | =0.8 | |
Mozilla Thunderbird | =0.9 | |
Mozilla Thunderbird | =1.0 | |
Mozilla Thunderbird | =1.0.1 | |
Mozilla Thunderbird | =1.0.2 | |
Mozilla Thunderbird | =1.0.3 | |
Mozilla Thunderbird | =1.0.4 | |
Mozilla Thunderbird | =1.0.5 | |
Mozilla Thunderbird | =1.0.6 | |
Mozilla Thunderbird | =1.0.7 | |
Mozilla Thunderbird | =1.0.8 | |
Mozilla Thunderbird | =1.5 | |
Mozilla Thunderbird | =1.5-beta2 | |
Mozilla Thunderbird | =1.5.0.1 | |
Mozilla Thunderbird | =1.5.0.2 | |
Mozilla Thunderbird | =1.5.0.3 | |
Mozilla Thunderbird | =1.5.0.4 | |
Mozilla Thunderbird | =1.5.0.5 | |
Mozilla Thunderbird | =1.5.0.6 | |
Mozilla Thunderbird | =1.5.0.7 | |
Mozilla Thunderbird | =1.5.0.8 | |
Mozilla Thunderbird | =1.5.0.9 | |
Mozilla Thunderbird | =1.5.0.10 | |
Mozilla Thunderbird | =1.5.0.11 | |
Mozilla Thunderbird | =1.5.0.12 | |
Mozilla Thunderbird | =1.5.0.13 | |
Mozilla Thunderbird | =1.5.0.14 | |
Mozilla Thunderbird | =1.5.1 | |
Mozilla Thunderbird | =1.5.2 | |
Mozilla Thunderbird | =2.0 | |
Mozilla Thunderbird | =2.0.0.0 | |
Mozilla Thunderbird | =2.0.0.1 | |
Mozilla Thunderbird | =2.0.0.2 | |
Mozilla Thunderbird | =2.0.0.3 | |
Mozilla Thunderbird | =2.0.0.4 | |
Mozilla Thunderbird | =2.0.0.5 | |
Mozilla Thunderbird | =2.0.0.6 | |
Mozilla Thunderbird | =2.0.0.7 | |
Mozilla Thunderbird | =2.0.0.8 | |
Mozilla Thunderbird | =2.0.0.9 | |
Mozilla Thunderbird | =2.0.0.12 | |
Mozilla Thunderbird | =2.0.0.14 | |
Mozilla Thunderbird | =2.0.0.16 | |
Mozilla Thunderbird | =2.0.0.17 | |
Mozilla Thunderbird | =2.0.0.18 | |
Mozilla Thunderbird | =2.0.0.19 | |
Mozilla Thunderbird | =2.0.0.21 | |
Mozilla Thunderbird | =2.0.0.22 | |
Mozilla Thunderbird | =2.0.0.23 | |
Mozilla Thunderbird | =3.0 | |
Mozilla Thunderbird | =3.0.1 | |
Mozilla Thunderbird | =3.0.2 | |
Mozilla Thunderbird | =3.0.3 | |
Mozilla Thunderbird | =3.0.4 | |
Mozilla Thunderbird | =3.0.5 | |
Mozilla Thunderbird | =3.1 | |
Mozilla Thunderbird | =3.1.1 | |
Mozilla Thunderbird | =3.1.2 | |
Mozilla Firefox | <=3.5.11 | |
Mozilla Firefox | =1.0 | |
Mozilla Firefox | =1.0-preview_release | |
Mozilla Firefox | =1.0.1 | |
Mozilla Firefox | =1.0.2 | |
Mozilla Firefox | =1.0.3 | |
Mozilla Firefox | =1.0.4 | |
Mozilla Firefox | =1.0.5 | |
Mozilla Firefox | =1.0.6 | |
Mozilla Firefox | =1.0.7 | |
Mozilla Firefox | =1.0.8 | |
Mozilla Firefox | =1.5 | |
Mozilla Firefox | =1.5-beta1 | |
Mozilla Firefox | =1.5-beta2 | |
Mozilla Firefox | =1.5.0.1 | |
Mozilla Firefox | =1.5.0.2 | |
Mozilla Firefox | =1.5.0.3 | |
Mozilla Firefox | =1.5.0.4 | |
Mozilla Firefox | =1.5.0.5 | |
Mozilla Firefox | =1.5.0.6 | |
Mozilla Firefox | =1.5.0.7 | |
Mozilla Firefox | =1.5.0.8 | |
Mozilla Firefox | =1.5.0.9 | |
Mozilla Firefox | =1.5.0.10 | |
Mozilla Firefox | =1.5.0.11 | |
Mozilla Firefox | =1.5.0.12 | |
Mozilla Firefox | =1.5.1 | |
Mozilla Firefox | =1.5.2 | |
Mozilla Firefox | =1.5.3 | |
Mozilla Firefox | =1.5.4 | |
Mozilla Firefox | =1.5.5 | |
Mozilla Firefox | =1.5.6 | |
Mozilla Firefox | =1.5.7 | |
Mozilla Firefox | =1.5.8 | |
Mozilla Firefox | =2.0 | |
Mozilla Firefox | =2.0.0.1 | |
Mozilla Firefox | =2.0.0.2 | |
Mozilla Firefox | =2.0.0.3 | |
Mozilla Firefox | =2.0.0.4 | |
Mozilla Firefox | =2.0.0.5 | |
Mozilla Firefox | =2.0.0.6 | |
Mozilla Firefox | =2.0.0.7 | |
Mozilla Firefox | =2.0.0.8 | |
Mozilla Firefox | =2.0.0.9 | |
Mozilla Firefox | =2.0.0.10 | |
Mozilla Firefox | =2.0.0.11 | |
Mozilla Firefox | =2.0.0.12 | |
Mozilla Firefox | =2.0.0.13 | |
Mozilla Firefox | =2.0.0.14 | |
Mozilla Firefox | =2.0.0.15 | |
Mozilla Firefox | =2.0.0.16 | |
Mozilla Firefox | =2.0.0.17 | |
Mozilla Firefox | =2.0.0.18 | |
Mozilla Firefox | =2.0.0.19 | |
Mozilla Firefox | =2.0.0.20 | |
Mozilla Firefox | =3.0 | |
Mozilla Firefox | =3.0.1 | |
Mozilla Firefox | =3.0.2 | |
Mozilla Firefox | =3.0.3 | |
Mozilla Firefox | =3.0.4 | |
Mozilla Firefox | =3.0.5 | |
Mozilla Firefox | =3.0.6 | |
Mozilla Firefox | =3.0.7 | |
Mozilla Firefox | =3.0.8 | |
Mozilla Firefox | =3.0.9 | |
Mozilla Firefox | =3.0.10 | |
Mozilla Firefox | =3.0.11 | |
Mozilla Firefox | =3.0.12 | |
Mozilla Firefox | =3.0.13 | |
Mozilla Firefox | =3.0.14 | |
Mozilla Firefox | =3.0.15 | |
Mozilla Firefox | =3.0.16 | |
Mozilla Firefox | =3.0.17 | |
Mozilla Firefox | =3.5 | |
Mozilla Firefox | =3.5.1 | |
Mozilla Firefox | =3.5.2 | |
Mozilla Firefox | =3.5.3 | |
Mozilla Firefox | =3.5.4 | |
Mozilla Firefox | =3.5.5 | |
Mozilla Firefox | =3.5.6 | |
Mozilla Firefox | =3.5.7 | |
Mozilla Firefox | =3.5.8 | |
Mozilla Firefox | =3.5.9 | |
Mozilla Firefox | =3.5.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2764 is considered a moderate severity vulnerability due to its potential exposure of intranet web servers.
To mitigate the effects of CVE-2010-2764, users should upgrade to the latest versions of Mozilla Firefox, Thunderbird, or SeaMonkey where the issue is addressed.
CVE-2010-2764 affects Mozilla Firefox before version 3.6.9, Thunderbird before version 3.1.3, and SeaMonkey before version 2.0.7.
CVE-2010-2764 can allow remote attackers to uncover the existence of internal web servers through improper handling of XMLHttpRequest statusText property.
Applications known to be vulnerable to CVE-2010-2764 include older versions of Mozilla Firefox, Thunderbird, and SeaMonkey.