Back

HIGH

Mozilla Crash and remote code execution in normalizeDocument (MFSA 2010-57)

Published Sep 9, 2010

Description

The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle the removal of DOM nodes during normalization, which might allow remote attackers to execute arbitrary code via vectors involving access to a deleted object.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 9, 2010
Updated Aug 7, 2024
Reserved Jul 14, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Sep 7, 2010
ENISA EUVD
Assigner mitre
Published Sep 9, 2010
Updated Aug 7, 2024
Exploited since n/a
EUVD-2010-2770