CVE-2010-3131: Critical severity Mozilla Firefox vulnerability
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .htm, .html, .jtx, .mfp, or .eml file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3131?
The severity of CVE-2010-3131 is classified as critical due to its potential for local and remote attackers to execute arbitrary code.
How do I fix CVE-2010-3131?
To fix CVE-2010-3131, update to the latest versions of Mozilla Firefox, Thunderbird, or SeaMonkey where this vulnerability has been addressed.
What systems are affected by CVE-2010-3131?
CVE-2010-3131 affects Mozilla Firefox versions before 3.5.12, Thunderbird versions before 3.0.7, and SeaMonkey versions before 2.0.7 on Windows XP.
What type of attack does CVE-2010-3131 enable?
CVE-2010-3131 enables local users and potentially remote attackers to conduct DLL hijacking attacks.
Can CVE-2010-3131 be exploited remotely?
Yes, CVE-2010-3131 can potentially be exploited remotely if an attacker can trick a user into opening a malicious file.