CVE Vulnerabilities

CVE-2010-0169

Published: Mar 25, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the browsers font and other CSS attributes, and potentially disrupt rendering of a web page, by forcing the browser to perform this erroneous stylesheet caching.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla3.0 (including)3.0 (including)
FirefoxMozilla3.0.1 (including)3.0.1 (including)
FirefoxMozilla3.0.10 (including)3.0.10 (including)
FirefoxMozilla3.0.11 (including)3.0.11 (including)
FirefoxMozilla3.0.12 (including)3.0.12 (including)
FirefoxMozilla3.0.13 (including)3.0.13 (including)
FirefoxMozilla3.0.14 (including)3.0.14 (including)
FirefoxMozilla3.0.15 (including)3.0.15 (including)
FirefoxMozilla3.0.16 (including)3.0.16 (including)
FirefoxMozilla3.0.17 (including)3.0.17 (including)
FirefoxMozilla3.5 (including)3.5 (including)
FirefoxMozilla3.5.1 (including)3.5.1 (including)
FirefoxMozilla3.5.2 (including)3.5.2 (including)
FirefoxMozilla3.5.3 (including)3.5.3 (including)
FirefoxMozilla3.5.4 (including)3.5.4 (including)
FirefoxMozilla3.5.5 (including)3.5.5 (including)
FirefoxMozilla3.5.6 (including)3.5.6 (including)
FirefoxMozilla3.5.7 (including)3.5.7 (including)
FirefoxMozilla3.6 (including)3.6 (including)
SeamonkeyMozilla*2.0.2 (including)
SeamonkeyMozilla1.1 (including)1.1 (including)
SeamonkeyMozilla1.1-alpha (including)1.1-alpha (including)
SeamonkeyMozilla1.1-beta (including)1.1-beta (including)
SeamonkeyMozilla1.1.1 (including)1.1.1 (including)
SeamonkeyMozilla1.1.2 (including)1.1.2 (including)
SeamonkeyMozilla1.1.3 (including)1.1.3 (including)
SeamonkeyMozilla1.1.4 (including)1.1.4 (including)
SeamonkeyMozilla1.1.5 (including)1.1.5 (including)
SeamonkeyMozilla1.1.5-1.1.10 (including)1.1.5-1.1.10 (including)
SeamonkeyMozilla1.1.6 (including)1.1.6 (including)
SeamonkeyMozilla1.1.7 (including)1.1.7 (including)
SeamonkeyMozilla1.1.8 (including)1.1.8 (including)
SeamonkeyMozilla1.1.9 (including)1.1.9 (including)
SeamonkeyMozilla1.1.10 (including)1.1.10 (including)
SeamonkeyMozilla1.1.11 (including)1.1.11 (including)
SeamonkeyMozilla1.1.12 (including)1.1.12 (including)
SeamonkeyMozilla1.1.13 (including)1.1.13 (including)
SeamonkeyMozilla1.1.14 (including)1.1.14 (including)
SeamonkeyMozilla1.1.15 (including)1.1.15 (including)
SeamonkeyMozilla1.1.16 (including)1.1.16 (including)
SeamonkeyMozilla1.1.17 (including)1.1.17 (including)
SeamonkeyMozilla1.1.18 (including)1.1.18 (including)
SeamonkeyMozilla1.1.19 (including)1.1.19 (including)
SeamonkeyMozilla2.0 (including)2.0 (including)
SeamonkeyMozilla2.0-alpha_1 (including)2.0-alpha_1 (including)
SeamonkeyMozilla2.0-alpha_2 (including)2.0-alpha_2 (including)
SeamonkeyMozilla2.0-alpha_3 (including)2.0-alpha_3 (including)
SeamonkeyMozilla2.0-beta_1 (including)2.0-beta_1 (including)
SeamonkeyMozilla2.0-beta_2 (including)2.0-beta_2 (including)
SeamonkeyMozilla2.0-rc1 (including)2.0-rc1 (including)
SeamonkeyMozilla2.0-rc2 (including)2.0-rc2 (including)
SeamonkeyMozilla2.0.1 (including)2.0.1 (including)
ThunderbirdMozilla*3.0.1 (including)
ThunderbirdMozilla1.5 (including)1.5 (including)
ThunderbirdMozilla1.5-beta2 (including)1.5-beta2 (including)
ThunderbirdMozilla1.5.0.1 (including)1.5.0.1 (including)
ThunderbirdMozilla1.5.0.2 (including)1.5.0.2 (including)
ThunderbirdMozilla1.5.0.3 (including)1.5.0.3 (including)
ThunderbirdMozilla1.5.0.4 (including)1.5.0.4 (including)
ThunderbirdMozilla1.5.0.5 (including)1.5.0.5 (including)
ThunderbirdMozilla1.5.0.6 (including)1.5.0.6 (including)
ThunderbirdMozilla1.5.0.7 (including)1.5.0.7 (including)
ThunderbirdMozilla1.5.0.8 (including)1.5.0.8 (including)
ThunderbirdMozilla1.5.0.9 (including)1.5.0.9 (including)
ThunderbirdMozilla1.5.0.10 (including)1.5.0.10 (including)
ThunderbirdMozilla1.5.0.11 (including)1.5.0.11 (including)
ThunderbirdMozilla1.5.0.12 (including)1.5.0.12 (including)
ThunderbirdMozilla1.5.0.13 (including)1.5.0.13 (including)
ThunderbirdMozilla1.5.0.14 (including)1.5.0.14 (including)
ThunderbirdMozilla1.5.1 (including)1.5.1 (including)
ThunderbirdMozilla1.5.2 (including)1.5.2 (including)
ThunderbirdMozilla2.0.0.0 (including)2.0.0.0 (including)
ThunderbirdMozilla2.0.0.3 (including)2.0.0.3 (including)
ThunderbirdMozilla2.0.0.4 (including)2.0.0.4 (including)
ThunderbirdMozilla2.0.0.5 (including)2.0.0.5 (including)
ThunderbirdMozilla2.0.0.6 (including)2.0.0.6 (including)
ThunderbirdMozilla2.0.0.7 (including)2.0.0.7 (including)
ThunderbirdMozilla2.0.0.8 (including)2.0.0.8 (including)
ThunderbirdMozilla2.0.0.9 (including)2.0.0.9 (including)
ThunderbirdMozilla2.0.0.12 (including)2.0.0.12 (including)
ThunderbirdMozilla2.0.0.14 (including)2.0.0.14 (including)
ThunderbirdMozilla2.0.0.16 (including)2.0.0.16 (including)
ThunderbirdMozilla2.0.0.17 (including)2.0.0.17 (including)
ThunderbirdMozilla2.0.0.18 (including)2.0.0.18 (including)
ThunderbirdMozilla2.0.0.19 (including)2.0.0.19 (including)
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.50.el3*
Red Hat Enterprise Linux 4RedHatfirefox-0:3.0.18-1.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-52.el4_8*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.12-25.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.0.18-1.el5_4*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.0.18-1.el5_4*
Red Hat Enterprise Linux 5RedHatthunderbird-0:2.0.0.24-2.el5_4*
FirefoxUbuntudapper*
FirefoxUbuntudevel*
FirefoxUbuntulucid*
FirefoxUbuntumaverick*
FirefoxUbuntunatty*
FirefoxUbuntuupstream*
SeamonkeyUbuntuhardy*
SeamonkeyUbuntuintrepid*
SeamonkeyUbuntujaunty*
SeamonkeyUbuntukarmic*
SeamonkeyUbuntulucid*
SeamonkeyUbuntuupstream*
ThunderbirdUbuntudevel*
ThunderbirdUbuntuhardy*
ThunderbirdUbuntujaunty*
ThunderbirdUbuntukarmic*
ThunderbirdUbuntulucid*
ThunderbirdUbuntumaverick*
ThunderbirdUbuntunatty*
ThunderbirdUbuntuupstream*
Xulrunner-1.9Ubuntuhardy*
Xulrunner-1.9Ubuntuintrepid*
Xulrunner-1.9Ubuntujaunty*
Xulrunner-1.9Ubuntuupstream*
Xulrunner-1.9.1Ubuntujaunty*
Xulrunner-1.9.1Ubuntukarmic*
Xulrunner-1.9.1Ubuntuupstream*

References