CVE
- Id
- 42763
- CVE No.
- CVE-2010-0179
- Status
- Candidate
- Description
- Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.
- Phase
- Assigned (20100106)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
466279 | 42763 | CVE-2010-0179 | CONFIRM:http://www.mozilla.org/security/announce/2010/mfsa2010-21.html | View |
466280 | 42763 | CVE-2010-0179 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=504021 | View |
466281 | 42763 | CVE-2010-0179 | CONFIRM:http://support.avaya.com/css/P8/documents/100124650 | View |
466282 | 42763 | CVE-2010-0179 | DEBIAN:DSA-2027 | View |
466283 | 42763 | CVE-2010-0179 | URL:http://www.debian.org/security/2010/dsa-2027 | View |
466284 | 42763 | CVE-2010-0179 | MANDRIVA:MDVSA-2010:070 | View |
466285 | 42763 | CVE-2010-0179 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2010:070 | View |
466286 | 42763 | CVE-2010-0179 | MANDRIVA:MDVSA-2010:251 | View |
466287 | 42763 | CVE-2010-0179 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2010:251 | View |
466288 | 42763 | CVE-2010-0179 | REDHAT:RHSA-2010:0332 | View |
466289 | 42763 | CVE-2010-0179 | URL:http://www.redhat.com/support/errata/RHSA-2010-0332.html | View |
466290 | 42763 | CVE-2010-0179 | SUSE:SUSE-SR:2010:013 | View |
466291 | 42763 | CVE-2010-0179 | URL:http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html | View |
466292 | 42763 | CVE-2010-0179 | SUSE:SUSE-SA:2011:003 | View |
466293 | 42763 | CVE-2010-0179 | URL:http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00002.html | View |
466294 | 42763 | CVE-2010-0179 | UBUNTU:USN-921-1 | View |
466295 | 42763 | CVE-2010-0179 | URL:http://ubuntu.com/usn/usn-921-1 | View |
466296 | 42763 | CVE-2010-0179 | BID:39124 | View |
466297 | 42763 | CVE-2010-0179 | URL:http://www.securityfocus.com/bid/39124 | View |
466298 | 42763 | CVE-2010-0179 | OVAL:oval:org.mitre.oval:def:6971 | View |
466299 | 42763 | CVE-2010-0179 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6971 | View |
466300 | 42763 | CVE-2010-0179 | OVAL:oval:org.mitre.oval:def:9446 | View |
466301 | 42763 | CVE-2010-0179 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9446 | View |
466302 | 42763 | CVE-2010-0179 | SECTRACK:1023783 | View |
466303 | 42763 | CVE-2010-0179 | URL:http://securitytracker.com/id?1023783 | View |
466304 | 42763 | CVE-2010-0179 | SECUNIA:3924 | View |
466305 | 42763 | CVE-2010-0179 | URL:http://secunia.com/advisories/3924 | View |
466306 | 42763 | CVE-2010-0179 | SECUNIA:39243 | View |
466307 | 42763 | CVE-2010-0179 | URL:http://secunia.com/advisories/39243 | View |
466308 | 42763 | CVE-2010-0179 | SECUNIA:39308 | View |
466309 | 42763 | CVE-2010-0179 | URL:http://secunia.com/advisories/39308 | View |
466310 | 42763 | CVE-2010-0179 | SECUNIA:39397 | View |
466311 | 42763 | CVE-2010-0179 | URL:http://secunia.com/advisories/39397 | View |
466312 | 42763 | CVE-2010-0179 | SECUNIA:42818 | View |
466313 | 42763 | CVE-2010-0179 | URL:http://secunia.com/advisories/42818 | View |
466314 | 42763 | CVE-2010-0179 | VUPEN:ADV-2010-0748 | View |
466315 | 42763 | CVE-2010-0179 | URL:http://www.vupen.com/english/advisories/2010/0748 | View |
466316 | 42763 | CVE-2010-0179 | VUPEN:ADV-2010-0764 | View |
466317 | 42763 | CVE-2010-0179 | URL:http://www.vupen.com/english/advisories/2010/0764 | View |
466318 | 42763 | CVE-2010-0179 | VUPEN:ADV-2010-0781 | View |
466319 | 42763 | CVE-2010-0179 | URL:http://www.vupen.com/english/advisories/2010/0781 | View |
466320 | 42763 | CVE-2010-0179 | VUPEN:ADV-2010-0849 | View |
466321 | 42763 | CVE-2010-0179 | URL:http://www.vupen.com/english/advisories/2010/0849 | View |
466322 | 42763 | CVE-2010-0179 | VUPEN:ADV-2011-0030 | View |
466323 | 42763 | CVE-2010-0179 | URL:http://www.vupen.com/english/advisories/2011/0030 | View |
466324 | 42763 | CVE-2010-0179 | XF:firefox-firebug-code-execution(57394) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
35912 | JVNDB-2010-001692 | 複数の Mozilla 製品の nsCycleCollector::MarkRoots 関数における任意のコードを実行される脆弱性 | 複数の Mozilla 製品の nsCycleCollector::MarkRoots 関数には、メニューのフレーム構築処理に関して不備があるため、任意のコードを実行される脆弱性が存在します。 | CVE-2010-0183 | 42763 | 9.3 | http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001692.html | View |