CVE-2010-2765: Buffer Overflow
Integer overflow in the FRAMESET element implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a large number of values in the cols (aka columns) attribute, leading to a heap-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2765?
CVE-2010-2765 is rated as a critical vulnerability allowing remote code execution.
How do I fix CVE-2010-2765?
To fix CVE-2010-2765, upgrade to Mozilla Firefox version 3.5.12 or later, Thunderbird version 3.0.7 or later, or SeaMonkey version 2.0.7 or later.
What software is affected by CVE-2010-2765?
CVE-2010-2765 affects Mozilla Firefox versions before 3.5.12, Thunderbird versions before 3.0.7, and SeaMonkey versions before 2.0.7.
What types of attacks can exploit CVE-2010-2765?
CVE-2010-2765 can be exploited through specially crafted HTML documents that can lead to arbitrary code execution.
Is there a workaround for CVE-2010-2765?
While the best solution is to update affected software, users can reduce risk by avoiding untrusted websites until the vulnerability is remedied.