CVE
- Id
- 42762
- CVE No.
- CVE-2010-0178
- Status
- Candidate
- Description
- Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mouse clicks as drag-and-drop actions, which allows remote attackers to execute arbitrary JavaScript with Chrome privileges by loading a chrome: URL and then loading a javascript: URL.
- Phase
- Assigned (20100106)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 466242 | 42762 | CVE-2010-0178 | CONFIRM:http://www.mozilla.org/security/announce/2010/mfsa2010-20.html | View |
| 466243 | 42762 | CVE-2010-0178 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=546909 | View |
| 466244 | 42762 | CVE-2010-0178 | DEBIAN:DSA-2027 | View |
| 466245 | 42762 | CVE-2010-0178 | URL:http://www.debian.org/security/2010/dsa-2027 | View |
| 466246 | 42762 | CVE-2010-0178 | MANDRIVA:MDVSA-2010:070 | View |
| 466247 | 42762 | CVE-2010-0178 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2010:070 | View |
| 466248 | 42762 | CVE-2010-0178 | REDHAT:RHSA-2010:0332 | View |
| 466249 | 42762 | CVE-2010-0178 | URL:http://www.redhat.com/support/errata/RHSA-2010-0332.html | View |
| 466250 | 42762 | CVE-2010-0178 | SUSE:SUSE-SR:2010:013 | View |
| 466251 | 42762 | CVE-2010-0178 | URL:http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html | View |
| 466252 | 42762 | CVE-2010-0178 | UBUNTU:USN-921-1 | View |
| 466253 | 42762 | CVE-2010-0178 | URL:http://ubuntu.com/usn/usn-921-1 | View |
| 466254 | 42762 | CVE-2010-0178 | OVAL:oval:org.mitre.oval:def:10460 | View |
| 466255 | 42762 | CVE-2010-0178 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10460 | View |
| 466256 | 42762 | CVE-2010-0178 | OVAL:oval:org.mitre.oval:def:6975 | View |
| 466257 | 42762 | CVE-2010-0178 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6975 | View |
| 466258 | 42762 | CVE-2010-0178 | SECTRACK:1023776 | View |
| 466259 | 42762 | CVE-2010-0178 | URL:http://securitytracker.com/id?1023776 | View |
| 466260 | 42762 | CVE-2010-0178 | SECUNIA:39136 | View |
| 466261 | 42762 | CVE-2010-0178 | URL:http://secunia.com/advisories/39136 | View |
| 466262 | 42762 | CVE-2010-0178 | SECUNIA:39240 | View |
| 466263 | 42762 | CVE-2010-0178 | URL:http://secunia.com/advisories/39240 | View |
| 466264 | 42762 | CVE-2010-0178 | SECUNIA:39243 | View |
| 466265 | 42762 | CVE-2010-0178 | URL:http://secunia.com/advisories/39243 | View |
| 466266 | 42762 | CVE-2010-0178 | SECUNIA:39308 | View |
| 466267 | 42762 | CVE-2010-0178 | URL:http://secunia.com/advisories/39308 | View |
| 466268 | 42762 | CVE-2010-0178 | SECUNIA:39397 | View |
| 466269 | 42762 | CVE-2010-0178 | URL:http://secunia.com/advisories/39397 | View |
| 466270 | 42762 | CVE-2010-0178 | VUPEN:ADV-2010-0748 | View |
| 466271 | 42762 | CVE-2010-0178 | URL:http://www.vupen.com/english/advisories/2010/0748 | View |
| 466272 | 42762 | CVE-2010-0178 | VUPEN:ADV-2010-0764 | View |
| 466273 | 42762 | CVE-2010-0178 | URL:http://www.vupen.com/english/advisories/2010/0764 | View |
| 466274 | 42762 | CVE-2010-0178 | VUPEN:ADV-2010-0781 | View |
| 466275 | 42762 | CVE-2010-0178 | URL:http://www.vupen.com/english/advisories/2010/0781 | View |
| 466276 | 42762 | CVE-2010-0178 | VUPEN:ADV-2010-0849 | View |
| 466277 | 42762 | CVE-2010-0178 | URL:http://www.vupen.com/english/advisories/2010/0849 | View |
| 466278 | 42762 | CVE-2010-0178 | XF:firefox-draganddrop-code-execution(57391) | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 35519 | JVNDB-2010-001299 | 複数の Mozilla 製品の XMLDocument::load 関数におけるアクセス制限を回避される脆弱性 | 複数の Mozilla 製品の XMLDocument::load 関数には、XML ドキュメントのコンテンツを読み込む際に nsIContentPolicy チェックを適切に実行しないため、アクセス制限を回避される脆弱性が存在します。 | CVE-2010-0182 | 42762 | 4.3 | http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001299.html | View |