CVE
- Id
- 46359
- CVE No.
- CVE-2010-3775
- Status
- Candidate
- Description
- Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle certain redirections involving data: URLs and Java LiveConnect scripts, which allows remote attackers to start processes, read arbitrary local files, and establish network connections via vectors involving a refresh value in the http-equiv attribute of a META element, which causes the wrong security principal to be used.
- Phase
- Assigned (20101005)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
505679 | 46359 | CVE-2010-3775 | CONFIRM:http://www.mozilla.org/security/announce/2010/mfsa2010-79.html | View |
505680 | 46359 | CVE-2010-3775 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=589041 | View |
505681 | 46359 | CVE-2010-3775 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=610525 | View |
505682 | 46359 | CVE-2010-3775 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=611897 | View |
505683 | 46359 | CVE-2010-3775 | CONFIRM:http://support.avaya.com/css/P8/documents/100124650 | View |
505684 | 46359 | CVE-2010-3775 | DEBIAN:DSA-2132 | View |
505685 | 46359 | CVE-2010-3775 | URL:http://www.debian.org/security/2010/dsa-2132 | View |
505686 | 46359 | CVE-2010-3775 | FEDORA:FEDORA-2010-18773 | View |
505687 | 46359 | CVE-2010-3775 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052032.html | View |
505688 | 46359 | CVE-2010-3775 | FEDORA:FEDORA-2010-18775 | View |
505689 | 46359 | CVE-2010-3775 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052022.html | View |
505690 | 46359 | CVE-2010-3775 | FEDORA:FEDORA-2010-18890 | View |
505691 | 46359 | CVE-2010-3775 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052502.html | View |
505692 | 46359 | CVE-2010-3775 | FEDORA:FEDORA-2010-18920 | View |
505693 | 46359 | CVE-2010-3775 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052504.html | View |
505694 | 46359 | CVE-2010-3775 | MANDRIVA:MDVSA-2010:251 | View |
505695 | 46359 | CVE-2010-3775 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2010:251 | View |
505696 | 46359 | CVE-2010-3775 | REDHAT:RHSA-2010:0966 | View |
505697 | 46359 | CVE-2010-3775 | URL:http://www.redhat.com/support/errata/RHSA-2010-0966.html | View |
505698 | 46359 | CVE-2010-3775 | REDHAT:RHSA-2010:0967 | View |
505699 | 46359 | CVE-2010-3775 | URL:http://www.redhat.com/support/errata/RHSA-2010-0967.html | View |
505700 | 46359 | CVE-2010-3775 | SUSE:SUSE-SA:2011:003 | View |
505701 | 46359 | CVE-2010-3775 | URL:http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00002.html | View |
505702 | 46359 | CVE-2010-3775 | UBUNTU:USN-1019-1 | View |
505703 | 46359 | CVE-2010-3775 | URL:http://www.ubuntu.com/usn/USN-1019-1 | View |
505704 | 46359 | CVE-2010-3775 | BID:45355 | View |
505705 | 46359 | CVE-2010-3775 | URL:http://www.securityfocus.com/bid/45355 | View |
505706 | 46359 | CVE-2010-3775 | OVAL:oval:org.mitre.oval:def:11666 | View |
505707 | 46359 | CVE-2010-3775 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11666 | View |
505708 | 46359 | CVE-2010-3775 | SECTRACK:1024848 | View |
505709 | 46359 | CVE-2010-3775 | URL:http://www.securitytracker.com/id?1024848 | View |
505710 | 46359 | CVE-2010-3775 | SECUNIA:42716 | View |
505711 | 46359 | CVE-2010-3775 | URL:http://secunia.com/advisories/42716 | View |
505712 | 46359 | CVE-2010-3775 | SECUNIA:42818 | View |
505713 | 46359 | CVE-2010-3775 | URL:http://secunia.com/advisories/42818 | View |
505714 | 46359 | CVE-2010-3775 | VUPEN:ADV-2011-0030 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
37077 | JVNDB-2010-002857 | Dovecot におけるアクセス制限を回避される脆弱性 | Dovecot は、非公開用の名前空間内の各メールボックス所有者に対して、admin パーミッションを付与するため、アクセス制限を回避される脆弱性が存在します。 | CVE-2010-3779 | 46359 | 3.5 | http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002857.html | View |