CVE-2010-2770: Buffer Overflow
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Mac OS X allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted font in a data: URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2770?
CVE-2010-2770 has a severity rating of medium, as it can cause denial of service and potentially allows arbitrary code execution.
How do I fix CVE-2010-2770?
To fix CVE-2010-2770, update to the latest versions of Mozilla Firefox, Thunderbird, or SeaMonkey that are no longer vulnerable.
What versions are affected by CVE-2010-2770?
CVE-2010-2770 affects Mozilla Firefox versions before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7.
What type of vulnerabilities does CVE-2010-2770 exploit?
CVE-2010-2770 exploits vulnerabilities in how the affected software processes crafted fonts, leading to memory corruption.
Can CVE-2010-2770 be exploited remotely?
Yes, CVE-2010-2770 can be exploited remotely by attackers through specially crafted data, resulting in application crashes or code execution.