CVE Vulnerabilities

CVE-2010-1207

Published: Jul 30, 2010 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node deletion.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 3.6.6 (including)
Firefox Mozilla 3.6 (including) 3.6 (including)
Firefox Mozilla 3.6.2 (including) 3.6.2 (including)
Firefox Mozilla 3.6.3 (including) 3.6.3 (including)
Firefox Mozilla 3.6.4 (including) 3.6.4 (including)
Thunderbird Mozilla * 3.1 (including)
Red Hat Enterprise Linux 4 RedHat firefox-0:3.6.7-2.el4 *
Red Hat Enterprise Linux 5 RedHat firefox-0:3.6.7-2.el5 *
Red Hat Enterprise Linux 5 RedHat xulrunner-0:1.9.2.7-2.el5 *
Firefox Ubuntu dapper *
Firefox Ubuntu devel *
Firefox Ubuntu hardy *
Firefox Ubuntu lucid *
Firefox-3.0 Ubuntu hardy *
Firefox-3.0 Ubuntu jaunty *
Firefox-3.5 Ubuntu jaunty *
Firefox-3.5 Ubuntu karmic *
Xulrunner-1.9.2 Ubuntu devel *
Xulrunner-1.9.2 Ubuntu hardy *
Xulrunner-1.9.2 Ubuntu jaunty *
Xulrunner-1.9.2 Ubuntu karmic *
Xulrunner-1.9.2 Ubuntu lucid *

References