CVE
- Id
- 46355
- CVE No.
- CVE-2010-3771
- Status
- Candidate
- Description
- Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to redirection to a chrome: URI.
- Phase
- Assigned (20101005)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
505553 | 46355 | CVE-2010-3771 | CONFIRM:http://www.mozilla.org/security/announce/2010/mfsa2010-76.html | View |
505554 | 46355 | CVE-2010-3771 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=609437 | View |
505555 | 46355 | CVE-2010-3771 | CONFIRM:http://support.avaya.com/css/P8/documents/100124650 | View |
505556 | 46355 | CVE-2010-3771 | DEBIAN:DSA-2132 | View |
505557 | 46355 | CVE-2010-3771 | URL:http://www.debian.org/security/2010/dsa-2132 | View |
505558 | 46355 | CVE-2010-3771 | FEDORA:FEDORA-2010-18773 | View |
505559 | 46355 | CVE-2010-3771 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052032.html | View |
505560 | 46355 | CVE-2010-3771 | FEDORA:FEDORA-2010-18775 | View |
505561 | 46355 | CVE-2010-3771 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052022.html | View |
505562 | 46355 | CVE-2010-3771 | FEDORA:FEDORA-2010-18890 | View |
505563 | 46355 | CVE-2010-3771 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052502.html | View |
505564 | 46355 | CVE-2010-3771 | FEDORA:FEDORA-2010-18920 | View |
505565 | 46355 | CVE-2010-3771 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052504.html | View |
505566 | 46355 | CVE-2010-3771 | MANDRIVA:MDVSA-2010:251 | View |
505567 | 46355 | CVE-2010-3771 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2010:251 | View |
505568 | 46355 | CVE-2010-3771 | REDHAT:RHSA-2010:0966 | View |
505569 | 46355 | CVE-2010-3771 | URL:http://www.redhat.com/support/errata/RHSA-2010-0966.html | View |
505570 | 46355 | CVE-2010-3771 | SUSE:SUSE-SA:2011:003 | View |
505571 | 46355 | CVE-2010-3771 | URL:http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00002.html | View |
505572 | 46355 | CVE-2010-3771 | UBUNTU:USN-1019-1 | View |
505573 | 46355 | CVE-2010-3771 | URL:http://www.ubuntu.com/usn/USN-1019-1 | View |
505574 | 46355 | CVE-2010-3771 | BID:45346 | View |
505575 | 46355 | CVE-2010-3771 | URL:http://www.securityfocus.com/bid/45346 | View |
505576 | 46355 | CVE-2010-3771 | OVAL:oval:org.mitre.oval:def:12343 | View |
505577 | 46355 | CVE-2010-3771 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12343 | View |
505578 | 46355 | CVE-2010-3771 | SECTRACK:1024848 | View |
505579 | 46355 | CVE-2010-3771 | URL:http://www.securitytracker.com/id?1024848 | View |
505580 | 46355 | CVE-2010-3771 | SECUNIA:42716 | View |
505581 | 46355 | CVE-2010-3771 | URL:http://secunia.com/advisories/42716 | View |
505582 | 46355 | CVE-2010-3771 | SECUNIA:42818 | View |
505583 | 46355 | CVE-2010-3771 | URL:http://secunia.com/advisories/42818 | View |
505584 | 46355 | CVE-2010-3771 | VUPEN:ADV-2011-0030 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
36794 | JVNDB-2010-002574 | Mozilla Firefox および SeaMonkey における複数の脆弱性 | Mozilla Firefox および SeaMonkey は、data: URL および Java LiveConnect スクリプトを含んだリダイレクションを適切に処理しないため、プロセスを開始されたり、任意のローカルファイルを読まれたり、あるいはネットワーク接続を確立される脆弱性が存在します。 | CVE-2010-3775 | 46355 | 9.3 | http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002574.html | View |