First published: Wed Dec 07 2011(Updated: )
The layout engine in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 executes different code for visited and unvisited links during the processing of Cascading Style Sheets (CSS) token sequences, which makes it easier for remote attackers to obtain sensitive information about visited web pages via a timing attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | =3.6.2 | |
Mozilla Firefox | =3.0.17 | |
Mozilla Firefox | =3.5.3 | |
Mozilla Firefox | =3.0.7 | |
Mozilla Firefox | =3.0.9 | |
Mozilla Firefox | =3.6.3 | |
Mozilla Firefox | =3.5.6 | |
Mozilla Firefox | =3.0.8 | |
Mozilla Firefox | =3.5 | |
Mozilla Firefox | =3.5.5 | |
Mozilla Firefox | =3.0.4 | |
Mozilla Firefox | =3.5.9 | |
Mozilla Firefox | =3.5.4 | |
Mozilla Firefox | =3.5.7 | |
Mozilla Firefox | =3.0.5 | |
Mozilla Firefox | =3.5.11 | |
Mozilla Firefox | =3.5.14 | |
Mozilla Firefox | =3.6.15 | |
Mozilla Firefox | =3.5.10 | |
Mozilla Firefox | =3.5.1 | |
Mozilla Firefox | =3.0.14 | |
Mozilla Firefox | =3.5.2 | |
Mozilla Firefox | =3.6.17 | |
Mozilla Firefox | <=3.6.24 | |
Mozilla Firefox | =3.6.11 | |
Mozilla Firefox | =3.6.8 | |
Mozilla Firefox | =3.0.10 | |
Mozilla Firefox | =3.6.9 | |
Mozilla Firefox | =3.6.14 | |
Mozilla Firefox | =3.0.12 | |
Mozilla Firefox | =3.0.3 | |
Mozilla Firefox | =3.6.12 | |
Mozilla Firefox | =3.6.23 | |
Mozilla Firefox | =3.0.6 | |
Mozilla Firefox | =3.0.15 | |
Mozilla Firefox | =3.5.12 | |
Mozilla Firefox | =3.6.6 | |
Mozilla Firefox | =3.0 | |
Mozilla Firefox | =3.6.21 | |
Mozilla Firefox | =3.6.16 | |
Mozilla Firefox | =3.0.1 | |
Mozilla Firefox | =3.6.1 | |
Mozilla Firefox | =3.6.10 | |
Mozilla Firefox | =3.6.19 | |
Mozilla Firefox | =3.5.13 | |
Mozilla Firefox | =3.0.2 | |
Mozilla Firefox | =3.5.8 | |
Mozilla Firefox | =3.6.7 | |
Mozilla Firefox | =3.6.4 | |
Mozilla Firefox | =3.6.18 | |
Mozilla Firefox | =3.5.15 | |
Mozilla Firefox | =3.6.20 | |
Mozilla Firefox | =3.6 | |
Mozilla Firefox | =3.6.22 | |
Mozilla Firefox | =3.6.13 | |
Mozilla Firefox | =3.0.13 | |
Mozilla Firefox | =3.0.16 | |
Mozilla Firefox | =3.0.11 | |
Mozilla Thunderbird | =3.0.8 | |
Mozilla Thunderbird | =3.0.5 | |
Mozilla Thunderbird | =3.1.8 | |
Mozilla Thunderbird | =3.1.11 | |
Mozilla Thunderbird | =3.0.9 | |
Mozilla Thunderbird | =3.0.1 | |
Mozilla Thunderbird | =3.1.14 | |
Mozilla Thunderbird | =3.1.7 | |
Mozilla Thunderbird | =3.1.2 | |
Mozilla Thunderbird | =3.1.9 | |
Mozilla Thunderbird | =3.1.1 | |
Mozilla Thunderbird | =3.1.15 | |
Mozilla Thunderbird | =3.1.4 | |
Mozilla Thunderbird | =3.0.7 | |
Mozilla Thunderbird | =3.0.6 | |
Mozilla Thunderbird | =3.0.10 | |
Mozilla Thunderbird | =3.0.3 | |
Mozilla Thunderbird | =3.1.5 | |
Mozilla Thunderbird | =3.0.11 | |
Mozilla Thunderbird | =3.1.10 | |
Mozilla Thunderbird | <=3.1.16 | |
Mozilla Thunderbird | =3.0.4 | |
Mozilla Thunderbird | =3.1.13 | |
Mozilla Thunderbird | =3.0 | |
Mozilla Thunderbird | =3.1 | |
Mozilla Thunderbird | =3.1.3 | |
Mozilla Thunderbird | =3.1.6 | |
Mozilla Thunderbird | =3.1.12 | |
Mozilla Thunderbird | =3.0.2 | |
Mozilla SeaMonkey | =2.0.10 | |
Mozilla SeaMonkey | =1.1.10 | |
Mozilla SeaMonkey | =1.0.3 | |
Mozilla SeaMonkey | =2.0.13 | |
Mozilla SeaMonkey | =1.1.8 | |
Mozilla SeaMonkey | =1.0.1 | |
Mozilla SeaMonkey | =1.1.7 | |
Mozilla SeaMonkey | =1.5.0.10 | |
Mozilla SeaMonkey | =1.0.6 | |
Mozilla SeaMonkey | =1.0.9 | |
Mozilla SeaMonkey | =1.1.3 | |
Mozilla SeaMonkey | =2.0.4 | |
Mozilla SeaMonkey | =1.0 | |
Mozilla SeaMonkey | =2.1-alpha2 | |
Mozilla SeaMonkey | =2.0.3 | |
Mozilla SeaMonkey | =2.0.2 | |
Mozilla SeaMonkey | =1.1.17 | |
Mozilla SeaMonkey | =2.0-alpha_2 | |
Mozilla SeaMonkey | =1.1.5 | |
Mozilla SeaMonkey | =2.0.8 | |
Mozilla SeaMonkey | =1.0.7 | |
Mozilla SeaMonkey | =1.0-beta | |
Mozilla SeaMonkey | =1.1-alpha | |
Mozilla SeaMonkey | =2.0-rc2 | |
Mozilla SeaMonkey | =2.0-alpha_3 | |
Mozilla SeaMonkey | =1.0-alpha | |
Mozilla SeaMonkey | =2.0a1 | |
Mozilla SeaMonkey | =1.1.12 | |
Mozilla SeaMonkey | =2.0.12 | |
Mozilla SeaMonkey | =1.1 | |
Mozilla SeaMonkey | =1.1.14 | |
Mozilla SeaMonkey | =2.0.11 | |
Mozilla SeaMonkey | =1.1.2 | |
Mozilla SeaMonkey | =2.0-beta_2 | |
Mozilla SeaMonkey | =1.0.2 | |
Mozilla SeaMonkey | =1.0.8 | |
Mozilla SeaMonkey | =1.1.11 | |
Mozilla SeaMonkey | =2.0-alpha_1 | |
Mozilla SeaMonkey | =1.5.0.9 | |
Mozilla SeaMonkey | =1.1-beta | |
Mozilla SeaMonkey | =1.1.1 | |
Mozilla SeaMonkey | <=2.1 | |
Mozilla SeaMonkey | =2.0.9 | |
Mozilla SeaMonkey | =2.1-alpha1 | |
Mozilla SeaMonkey | =1.5.0.8 | |
Mozilla SeaMonkey | =2.0.1 | |
Mozilla SeaMonkey | =1.0.5 | |
Mozilla SeaMonkey | =1.1.15 | |
Mozilla SeaMonkey | =2.0.14 | |
Mozilla SeaMonkey | =1.1.6 | |
Mozilla SeaMonkey | =2.0.7 | |
Mozilla SeaMonkey | =1.1.16 | |
Mozilla SeaMonkey | =2.0-beta_1 | |
Mozilla SeaMonkey | =1.1.19 | |
Mozilla SeaMonkey | =2.0.5 | |
Mozilla SeaMonkey | =2.0-rc1 | |
Mozilla SeaMonkey | =1.0.4 | |
Mozilla SeaMonkey | =1.1.9 | |
Mozilla SeaMonkey | =1.1.13 | |
Mozilla SeaMonkey | =1.1.18 | |
Mozilla SeaMonkey | =2.0.6 | |
Mozilla SeaMonkey | =2.0 | |
Mozilla SeaMonkey | =1.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-5074 is considered a moderate severity vulnerability as it allows remote attackers to obtain sensitive information from affected software.
To mitigate CVE-2010-5074, users should upgrade to versions of Mozilla Firefox, Thunderbird, or SeaMonkey that are higher than those specified in the vulnerability report.
CVE-2010-5074 affects Mozilla Firefox versions before 4.0, Thunderbird versions before 3.3, and SeaMonkey versions before 2.1.
CVE-2010-5074 facilitates an attack that exploits differences in code execution for visited and unvisited links in CSS, potentially leading to information disclosure.
Temporary workarounds for CVE-2010-5074 include disabling certain CSS features or using different browsers until a patch is applied.