CVE-2010-3168: Buffer Overflow
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict the role of property changes in triggering XUL tree removal, which allows remote attackers to cause a denial of service (deleted memory access and application crash) or possibly execute arbitrary code by setting unspecified properties.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3168?
CVE-2010-3168 has been classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2010-3168?
To fix CVE-2010-3168, upgrade to Mozilla Firefox version 3.6.9 or later, Thunderbird version 3.1.3 or later, or SeaMonkey version 2.0.7 or later.
Which versions of software are affected by CVE-2010-3168?
CVE-2010-3168 affects Mozilla Firefox versions prior to 3.5.12, all 3.6.x versions before 3.6.9, Thunderbird versions before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey versions before 2.0.7.
What type of vulnerability is CVE-2010-3168?
CVE-2010-3168 is a denial of service vulnerability that arises from improper handling of memory in affected applications.
Can CVE-2010-3168 be exploited by attackers?
Yes, remote attackers can exploit CVE-2010-3168 to cause a denial of service by triggering deleted memory access.