CVE
- Id
- 42763
- CVE No.
- CVE-2010-0179
- Status
- Candidate
- Description
- Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.
- Phase
- Assigned (20100106)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 466279 | 42763 | CVE-2010-0179 | CONFIRM:http://www.mozilla.org/security/announce/2010/mfsa2010-21.html | View |
| 466280 | 42763 | CVE-2010-0179 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=504021 | View |
| 466281 | 42763 | CVE-2010-0179 | CONFIRM:http://support.avaya.com/css/P8/documents/100124650 | View |
| 466282 | 42763 | CVE-2010-0179 | DEBIAN:DSA-2027 | View |
| 466283 | 42763 | CVE-2010-0179 | URL:http://www.debian.org/security/2010/dsa-2027 | View |
| 466284 | 42763 | CVE-2010-0179 | MANDRIVA:MDVSA-2010:070 | View |
| 466285 | 42763 | CVE-2010-0179 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2010:070 | View |
| 466286 | 42763 | CVE-2010-0179 | MANDRIVA:MDVSA-2010:251 | View |
| 466287 | 42763 | CVE-2010-0179 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2010:251 | View |
| 466288 | 42763 | CVE-2010-0179 | REDHAT:RHSA-2010:0332 | View |
| 466289 | 42763 | CVE-2010-0179 | URL:http://www.redhat.com/support/errata/RHSA-2010-0332.html | View |
| 466290 | 42763 | CVE-2010-0179 | SUSE:SUSE-SR:2010:013 | View |
| 466291 | 42763 | CVE-2010-0179 | URL:http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html | View |
| 466292 | 42763 | CVE-2010-0179 | SUSE:SUSE-SA:2011:003 | View |
| 466293 | 42763 | CVE-2010-0179 | URL:http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00002.html | View |
| 466294 | 42763 | CVE-2010-0179 | UBUNTU:USN-921-1 | View |
| 466295 | 42763 | CVE-2010-0179 | URL:http://ubuntu.com/usn/usn-921-1 | View |
| 466296 | 42763 | CVE-2010-0179 | BID:39124 | View |
| 466297 | 42763 | CVE-2010-0179 | URL:http://www.securityfocus.com/bid/39124 | View |
| 466298 | 42763 | CVE-2010-0179 | OVAL:oval:org.mitre.oval:def:6971 | View |
| 466299 | 42763 | CVE-2010-0179 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6971 | View |
| 466300 | 42763 | CVE-2010-0179 | OVAL:oval:org.mitre.oval:def:9446 | View |
| 466301 | 42763 | CVE-2010-0179 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9446 | View |
| 466302 | 42763 | CVE-2010-0179 | SECTRACK:1023783 | View |
| 466303 | 42763 | CVE-2010-0179 | URL:http://securitytracker.com/id?1023783 | View |
| 466304 | 42763 | CVE-2010-0179 | SECUNIA:3924 | View |
| 466305 | 42763 | CVE-2010-0179 | URL:http://secunia.com/advisories/3924 | View |
| 466306 | 42763 | CVE-2010-0179 | SECUNIA:39243 | View |
| 466307 | 42763 | CVE-2010-0179 | URL:http://secunia.com/advisories/39243 | View |
| 466308 | 42763 | CVE-2010-0179 | SECUNIA:39308 | View |
| 466309 | 42763 | CVE-2010-0179 | URL:http://secunia.com/advisories/39308 | View |
| 466310 | 42763 | CVE-2010-0179 | SECUNIA:39397 | View |
| 466311 | 42763 | CVE-2010-0179 | URL:http://secunia.com/advisories/39397 | View |
| 466312 | 42763 | CVE-2010-0179 | SECUNIA:42818 | View |
| 466313 | 42763 | CVE-2010-0179 | URL:http://secunia.com/advisories/42818 | View |
| 466314 | 42763 | CVE-2010-0179 | VUPEN:ADV-2010-0748 | View |
| 466315 | 42763 | CVE-2010-0179 | URL:http://www.vupen.com/english/advisories/2010/0748 | View |
| 466316 | 42763 | CVE-2010-0179 | VUPEN:ADV-2010-0764 | View |
| 466317 | 42763 | CVE-2010-0179 | URL:http://www.vupen.com/english/advisories/2010/0764 | View |
| 466318 | 42763 | CVE-2010-0179 | VUPEN:ADV-2010-0781 | View |
| 466319 | 42763 | CVE-2010-0179 | URL:http://www.vupen.com/english/advisories/2010/0781 | View |
| 466320 | 42763 | CVE-2010-0179 | VUPEN:ADV-2010-0849 | View |
| 466321 | 42763 | CVE-2010-0179 | URL:http://www.vupen.com/english/advisories/2010/0849 | View |
| 466322 | 42763 | CVE-2010-0179 | VUPEN:ADV-2011-0030 | View |
| 466323 | 42763 | CVE-2010-0179 | URL:http://www.vupen.com/english/advisories/2011/0030 | View |
| 466324 | 42763 | CVE-2010-0179 | XF:firefox-firebug-code-execution(57394) | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 35912 | JVNDB-2010-001692 | 複数の Mozilla 製品の nsCycleCollector::MarkRoots 関数における任意のコードを実行される脆弱性 | 複数の Mozilla 製品の nsCycleCollector::MarkRoots 関数には、メニューのフレーム構築処理に関して不備があるため、任意のコードを実行される脆弱性が存在します。 | CVE-2010-0183 | 42763 | 9.3 | http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001692.html | View |