CVE Vulnerabilities

CVE-2010-0176

Published: Apr 05, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to deleted elements, related to a dangling pointer vulnerability.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla3.6 (including)3.6 (including)
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.52.el3*
Red Hat Enterprise Linux 4RedHatfirefox-0:3.0.19-1.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-54.el4_8*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.12-28.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.0.19-1.el5_5*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.0.19-1.el5_5*
Red Hat Enterprise Linux 5RedHatthunderbird-0:2.0.0.24-6.el5*
FirefoxUbuntudapper*
FirefoxUbuntudevel*
FirefoxUbuntulucid*
FirefoxUbuntuupstream*
SeamonkeyUbuntuhardy*
SeamonkeyUbuntuintrepid*
SeamonkeyUbuntujaunty*
SeamonkeyUbuntukarmic*
SeamonkeyUbuntulucid*
SeamonkeyUbuntuupstream*
ThunderbirdUbuntudevel*
ThunderbirdUbuntuhardy*
ThunderbirdUbuntuintrepid*
ThunderbirdUbuntujaunty*
ThunderbirdUbuntukarmic*
ThunderbirdUbuntulucid*
ThunderbirdUbuntuupstream*
Xulrunner-1.9Ubuntuhardy*
Xulrunner-1.9Ubuntuintrepid*
Xulrunner-1.9Ubuntujaunty*
Xulrunner-1.9Ubuntuupstream*
Xulrunner-1.9.1Ubuntujaunty*
Xulrunner-1.9.1Ubuntukarmic*
Xulrunner-1.9.1Ubuntuupstream*

References