CVE-2010-2767: Critical severity Mozilla Firefox vulnerability
The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle destruction of the DOM plugin array, which might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted access to the navigator object, related to a "dangling pointer vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2767?
CVE-2010-2767 has a medium severity rating, indicating a moderate risk of denial of service for affected users.
How do I fix CVE-2010-2767?
To fix CVE-2010-2767, users should update Mozilla Firefox, Thunderbird, or SeaMonkey to the latest versions that have addressed this vulnerability.
Which versions of software are affected by CVE-2010-2767?
CVE-2010-2767 affects Mozilla Firefox versions prior to 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7.
What kind of attack does CVE-2010-2767 enable?
CVE-2010-2767 enables remote attackers to cause a denial of service through improper handling of the DOM plugin array.
Is CVE-2010-2767 still a concern today?
While CVE-2010-2767 was relevant at the time of its disclosure, users should focus on keeping their software updated to mitigate any potential remnants of older vulnerabilities.