CVE
- Id
- 43781
- CVE No.
- CVE-2010-1197
- Status
- Candidate
- Description
- Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not properly handle situations in which both "Content-Disposition: attachment" and "Content-Type: multipart" are present in HTTP headers, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an uploaded HTML document.
- Phase
- Assigned (20100330)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
476842 | 43781 | CVE-2010-1197 | CONFIRM:http://www.mozilla.org/security/announce/2010/mfsa2010-32.html | View |
476843 | 43781 | CVE-2010-1197 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=537120 | View |
476844 | 43781 | CVE-2010-1197 | CONFIRM:http://support.avaya.com/css/P8/documents/100091069 | View |
476845 | 43781 | CVE-2010-1197 | FEDORA:FEDORA-2010-10344 | View |
476846 | 43781 | CVE-2010-1197 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043369.html | View |
476847 | 43781 | CVE-2010-1197 | FEDORA:FEDORA-2010-10361 | View |
476848 | 43781 | CVE-2010-1197 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043405.html | View |
476849 | 43781 | CVE-2010-1197 | MANDRIVA:MDVSA-2010:125 | View |
476850 | 43781 | CVE-2010-1197 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2010:125 | View |
476851 | 43781 | CVE-2010-1197 | REDHAT:RHSA-2010:0499 | View |
476852 | 43781 | CVE-2010-1197 | URL:http://www.redhat.com/support/errata/RHSA-2010-0499.html | View |
476853 | 43781 | CVE-2010-1197 | REDHAT:RHSA-2010:0500 | View |
476854 | 43781 | CVE-2010-1197 | URL:http://www.redhat.com/support/errata/RHSA-2010-0500.html | View |
476855 | 43781 | CVE-2010-1197 | REDHAT:RHSA-2010:0501 | View |
476856 | 43781 | CVE-2010-1197 | URL:http://www.redhat.com/support/errata/RHSA-2010-0501.html | View |
476857 | 43781 | CVE-2010-1197 | SUSE:SUSE-SA:2010:030 | View |
476858 | 43781 | CVE-2010-1197 | URL:http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.html | View |
476859 | 43781 | CVE-2010-1197 | UBUNTU:USN-930-1 | View |
476860 | 43781 | CVE-2010-1197 | URL:http://ubuntu.com/usn/usn-930-1 | View |
476861 | 43781 | CVE-2010-1197 | UBUNTU:USN-930-2 | View |
476862 | 43781 | CVE-2010-1197 | URL:http://www.ubuntu.com/usn/usn-930-2 | View |
476863 | 43781 | CVE-2010-1197 | BID:41050 | View |
476864 | 43781 | CVE-2010-1197 | URL:http://www.securityfocus.com/bid/41050 | View |
476865 | 43781 | CVE-2010-1197 | BID:41103 | View |
476866 | 43781 | CVE-2010-1197 | URL:http://www.securityfocus.com/bid/41103 | View |
476867 | 43781 | CVE-2010-1197 | OVAL:oval:org.mitre.oval:def:10168 | View |
476868 | 43781 | CVE-2010-1197 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10168 | View |
476869 | 43781 | CVE-2010-1197 | OVAL:oval:org.mitre.oval:def:14186 | View |
476870 | 43781 | CVE-2010-1197 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14186 | View |
476871 | 43781 | CVE-2010-1197 | SECTRACK:1024138 | View |
476872 | 43781 | CVE-2010-1197 | URL:http://www.securitytracker.com/id?1024138 | View |
476873 | 43781 | CVE-2010-1197 | SECUNIA:40326 | View |
476874 | 43781 | CVE-2010-1197 | URL:http://secunia.com/advisories/40326 | View |
476875 | 43781 | CVE-2010-1197 | SECUNIA:40401 | View |
476876 | 43781 | CVE-2010-1197 | URL:http://secunia.com/advisories/40401 | View |
476877 | 43781 | CVE-2010-1197 | SECUNIA:40481 | View |
476878 | 43781 | CVE-2010-1197 | URL:http://secunia.com/advisories/40481 | View |
476879 | 43781 | CVE-2010-1197 | VUPEN:ADV-2010-1551 | View |
476880 | 43781 | CVE-2010-1197 | URL:http://www.vupen.com/english/advisories/2010/1551 | View |
476881 | 43781 | CVE-2010-1197 | VUPEN:ADV-2010-1556 | View |
476882 | 43781 | CVE-2010-1197 | URL:http://www.vupen.com/english/advisories/2010/1556 | View |
476883 | 43781 | CVE-2010-1197 | VUPEN:ADV-2010-1557 | View |
476884 | 43781 | CVE-2010-1197 | URL:http://www.vupen.com/english/advisories/2010/1557 | View |
476885 | 43781 | CVE-2010-1197 | VUPEN:ADV-2010-1640 | View |
476886 | 43781 | CVE-2010-1197 | URL:http://www.vupen.com/english/advisories/2010/1640 | View |
476887 | 43781 | CVE-2010-1197 | VUPEN:ADV-2010-1773 | View |
476888 | 43781 | CVE-2010-1197 | URL:http://www.vupen.com/english/advisories/2010/1773 | View |
476889 | 43781 | CVE-2010-1197 | VUPEN:ADV-2010-1592 | View |
476890 | 43781 | CVE-2010-1197 | URL:http://www.vupen.com/english/advisories/2010/1592 | View |
476891 | 43781 | CVE-2010-1197 | XF:firefox-contentdisposition-security-bypass(59667) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
35907 | JVNDB-2010-001687 | 複数の Mozilla 製品 のブラウザエンジンにおける任意のコードを実行される脆弱性 | 複数の Mozilla 製品のブラウザエンジンには、サービス運用妨害 (DoS) 状態となる、または任意のコードを実行される脆弱性が存在します。 | CVE-2010-1201 | 43781 | 9.3 | http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001687.html | View |