CVE Vulnerabilities

CVE-2010-1207

Published: Jul 30, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node deletion.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*3.6.6 (including)
FirefoxMozilla3.6 (including)3.6 (including)
FirefoxMozilla3.6.2 (including)3.6.2 (including)
FirefoxMozilla3.6.3 (including)3.6.3 (including)
FirefoxMozilla3.6.4 (including)3.6.4 (including)
ThunderbirdMozilla*3.1 (including)
Red Hat Enterprise Linux 4RedHatfirefox-0:3.6.7-2.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.6.7-2.el5*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.2.7-2.el5*
FirefoxUbuntudapper*
FirefoxUbuntudevel*
FirefoxUbuntuhardy*
FirefoxUbuntulucid*
Firefox-3.0Ubuntuhardy*
Firefox-3.0Ubuntujaunty*
Firefox-3.5Ubuntujaunty*
Firefox-3.5Ubuntukarmic*
Xulrunner-1.9.2Ubuntudevel*
Xulrunner-1.9.2Ubuntuhardy*
Xulrunner-1.9.2Ubuntujaunty*
Xulrunner-1.9.2Ubuntukarmic*
Xulrunner-1.9.2Ubuntulucid*

References