CVE-2010-2766: Code Injection
The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle the removal of DOM nodes during normalization, which might allow remote attackers to execute arbitrary code via vectors involving access to a deleted object.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2766?
CVE-2010-2766 is categorized as a critical vulnerability, as it may allow remote attackers to execute arbitrary code.
Which versions are affected by CVE-2010-2766?
CVE-2010-2766 affects Mozilla Firefox versions prior to 3.5.12 and 3.6.x prior to 3.6.9, as well as Thunderbird and SeaMonkey versions before certain thresholds.
How can I fix CVE-2010-2766?
To fix CVE-2010-2766, users should update Mozilla Firefox, Thunderbird, and SeaMonkey to the latest versions that have patched this vulnerability.
What types of attacks can CVE-2010-2766 facilitate?
CVE-2010-2766 can facilitate remote code execution attacks, allowing attackers to potentially gain control over the affected system.
Is there a workaround for CVE-2010-2766?
There are no reliable workarounds for CVE-2010-2766, and the best mitigation strategy is to update to the fixed versions.