CVE-2010-3771: Medium severity Mozilla Firefox vulnerability
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to redirection to a chrome: URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3771?
CVE-2010-3771 is classified as a medium severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2010-3771?
To fix CVE-2010-3771, upgrade your Mozilla Firefox version to at least 3.5.16 or 3.6.13, or SeaMonkey to at least 2.0.11.
What types of attacks can exploit CVE-2010-3771?
CVE-2010-3771 can be exploited through specially crafted web pages that redirect users to the vulnerable about:blank pages.
Which versions of Firefox are affected by CVE-2010-3771?
Versions of Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13 are affected by CVE-2010-3771.
Is CVE-2010-3771 a browser-specific vulnerability?
Yes, CVE-2010-3771 specifically affects Mozilla Firefox and SeaMonkey browsers.