CVE Vulnerabilities

CVE-2010-2755

Published: Jul 30, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not properly free memory in the parameter array of a plugin instance, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted HTML document, related to the DATA and SRC attributes of an OBJECT element. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-1214.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla3.6.7 (including)3.6.7 (including)
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.58.el3*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-61.el4*
Red Hat Enterprise Linux 4RedHatfirefox-0:3.6.7-3.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.6.7-3.el5*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.2.7-3.el5*
FirefoxUbuntudapper*
FirefoxUbuntudevel*
FirefoxUbuntuhardy*
FirefoxUbuntulucid*
FirefoxUbuntuupstream*
Firefox-3.0Ubuntuhardy*
Firefox-3.0Ubuntujaunty*
Firefox-3.0Ubuntuupstream*
Firefox-3.5Ubuntujaunty*
Firefox-3.5Ubuntukarmic*
Firefox-3.5Ubuntuupstream*
Xulrunner-1.9.2Ubuntudevel*
Xulrunner-1.9.2Ubuntuhardy*
Xulrunner-1.9.2Ubuntujaunty*
Xulrunner-1.9.2Ubuntukarmic*
Xulrunner-1.9.2Ubuntulucid*
Xulrunner-1.9.2Ubuntuupstream*

References