CVE-2010-3775: Critical severity Mozilla Firefox vulnerability
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle certain redirections involving data: URLs and Java LiveConnect scripts, which allows remote attackers to start processes, read arbitrary local files, and establish network connections via vectors involving a refresh value in the http-equiv attribute of a META element, which causes the wrong security principal to be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3775?
CVE-2010-3775 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary processes and read local files.
How do I fix CVE-2010-3775?
To fix CVE-2010-3775, update to the latest version of Mozilla Firefox or SeaMonkey that addresses this vulnerability.
Which versions are affected by CVE-2010-3775?
CVE-2010-3775 affects Mozilla Firefox versions prior to 3.5.16 and 3.6.x prior to 3.6.13, as well as certain versions of SeaMonkey.
What types of attacks can exploit CVE-2010-3775?
CVE-2010-3775 can be exploited to launch attacks that execute arbitrary processes, read local files, and establish network connections without user consent.
Is there a workaround for CVE-2010-3775 if I cannot update immediately?
As a temporary workaround for CVE-2010-3775, consider limiting the use of data: URLs in your browser settings until a full update can be applied.