CVE
- Id
- 46354
- CVE No.
- CVE-2010-3770
- Status
- Candidate
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allow remote attackers to inject arbitrary web script or HTML via (1) x-mac-arabic, (2) x-mac-farsi, or (3) x-mac-hebrew characters that may be converted to angle brackets during rendering.
- Phase
- Assigned (20101005)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
505521 | 46354 | CVE-2010-3770 | CONFIRM:http://www.mozilla.org/security/announce/2010/mfsa2010-84.html | View |
505522 | 46354 | CVE-2010-3770 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=601429 | View |
505523 | 46354 | CVE-2010-3770 | CONFIRM:http://support.avaya.com/css/P8/documents/100124650 | View |
505524 | 46354 | CVE-2010-3770 | DEBIAN:DSA-2132 | View |
505525 | 46354 | CVE-2010-3770 | URL:http://www.debian.org/security/2010/dsa-2132 | View |
505526 | 46354 | CVE-2010-3770 | FEDORA:FEDORA-2010-18773 | View |
505527 | 46354 | CVE-2010-3770 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052032.html | View |
505528 | 46354 | CVE-2010-3770 | FEDORA:FEDORA-2010-18775 | View |
505529 | 46354 | CVE-2010-3770 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052022.html | View |
505530 | 46354 | CVE-2010-3770 | FEDORA:FEDORA-2010-18890 | View |
505531 | 46354 | CVE-2010-3770 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052502.html | View |
505532 | 46354 | CVE-2010-3770 | FEDORA:FEDORA-2010-18920 | View |
505533 | 46354 | CVE-2010-3770 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052504.html | View |
505534 | 46354 | CVE-2010-3770 | MANDRIVA:MDVSA-2010:251 | View |
505535 | 46354 | CVE-2010-3770 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2010:251 | View |
505536 | 46354 | CVE-2010-3770 | REDHAT:RHSA-2010:0966 | View |
505537 | 46354 | CVE-2010-3770 | URL:http://www.redhat.com/support/errata/RHSA-2010-0966.html | View |
505538 | 46354 | CVE-2010-3770 | SUSE:SUSE-SA:2011:003 | View |
505539 | 46354 | CVE-2010-3770 | URL:http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00002.html | View |
505540 | 46354 | CVE-2010-3770 | UBUNTU:USN-1019-1 | View |
505541 | 46354 | CVE-2010-3770 | URL:http://www.ubuntu.com/usn/USN-1019-1 | View |
505542 | 46354 | CVE-2010-3770 | BID:45353 | View |
505543 | 46354 | CVE-2010-3770 | URL:http://www.securityfocus.com/bid/45353 | View |
505544 | 46354 | CVE-2010-3770 | OVAL:oval:org.mitre.oval:def:12348 | View |
505545 | 46354 | CVE-2010-3770 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12348 | View |
505546 | 46354 | CVE-2010-3770 | SECTRACK:1024851 | View |
505547 | 46354 | CVE-2010-3770 | URL:http://www.securitytracker.com/id?1024851 | View |
505548 | 46354 | CVE-2010-3770 | SECUNIA:42716 | View |
505549 | 46354 | CVE-2010-3770 | URL:http://secunia.com/advisories/42716 | View |
505550 | 46354 | CVE-2010-3770 | SECUNIA:42818 | View |
505551 | 46354 | CVE-2010-3770 | URL:http://secunia.com/advisories/42818 | View |
505552 | 46354 | CVE-2010-3770 | VUPEN:ADV-2011-0030 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
36798 | JVNDB-2010-002578 | Mozilla Firefox および SeaMonkey におけるロケーションバーを偽装される脆弱性 | Mozilla Firefox および SeaMonkey の netwerk/base/public/nsNetUtil.h 内にある NS_SecurityCompareURIs 関数は、about:neterror および about:certerror ページを適切に処理しないため、ロケーションバーを偽装される脆弱性が存在します。 | CVE-2010-3774 | 46354 | 4.3 | http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002578.html | View |