Mozilla Copy-and-paste or drag-and-drop into designMode document allows XSS (MFSA 2010-62)
Published Sep 9, 2010
4.3
MEDIUMCVSS 2.0
EPSS 2.07%
Description
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode property is enabled.
Affected products
No data.
Configuration 1
Configuration 2
- ≤ 2.0.6
- 1.0
- 1.0
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.0.9
- 1.1
- 1.1
- 1.1
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.5
- 1.1.6
- 1.1.7
- 1.1.8
- 1.1.9
- 1.1.10
- 1.1.11
- 1.1.12
- 1.1.13
- 1.1.14
- 1.1.15
- 1.1.16
- 1.1.17
- 1.1.18
- 1.1.19
- 1.5.0.8
- 1.5.0.9
- 1.5.0.10
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.0a1pre
Configuration 3
- ≤ 3.0.6
- 0.1
- 0.2
- 0.3
- 0.4
- 0.5
- 0.6
- 0.7
- 0.7.1
- 0.7.2
- 0.7.3
- 0.8
- 0.9
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.5
- 1.5
- 1.5.0.1
- 1.5.0.2
- 1.5.0.3
- 1.5.0.4
- 1.5.0.5
- 1.5.0.6
- 1.5.0.7
- 1.5.0.8
- 1.5.0.9
- 1.5.0.10
- 1.5.0.11
- 1.5.0.12
- 1.5.0.13
- 1.5.0.14
- 1.5.1
- 1.5.2
- 2.0
- 2.0.0.0
- 2.0.0.1
- 2.0.0.2
- 2.0.0.3
- 2.0.0.4
- 2.0.0.5
- 2.0.0.6
- 2.0.0.7
- 2.0.0.8
- 2.0.0.9
- 2.0.0.12
- 2.0.0.14
- 2.0.0.16
- 2.0.0.17
- 2.0.0.18
- 2.0.0.19
- 2.0.0.21
- 2.0.0.22
- 2.0.0.23
- 3.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.1
- 3.1.1
- 3.1.2
Configuration 4
- ≤ 3.5.11
- 1.0
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.5
- 1.5
- 1.5
- 1.5.0.1
- 1.5.0.2
- 1.5.0.3
- 1.5.0.4
- 1.5.0.5
- 1.5.0.6
- 1.5.0.7
- 1.5.0.8
- 1.5.0.9
- 1.5.0.10
- 1.5.0.11
- 1.5.0.12
- 1.5.1
- 1.5.2
- 1.5.3
- 1.5.4
- 1.5.5
- 1.5.6
- 1.5.7
- 1.5.8
- 2.0
- 2.0.0.1
- 2.0.0.2
- 2.0.0.3
- 2.0.0.4
- 2.0.0.5
- 2.0.0.6
- 2.0.0.7
- 2.0.0.8
- 2.0.0.9
- 2.0.0.10
- 2.0.0.11
- 2.0.0.12
- 2.0.0.13
- 2.0.0.14
- 2.0.0.15
- 2.0.0.16
- 2.0.0.17
- 2.0.0.18
- 2.0.0.19
- 2.0.0.20
- 3.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.7
- 3.0.8
- 3.0.9
- 3.0.10
- 3.0.11
- 3.0.12
- 3.0.13
- 3.0.14
- 3.0.15
- 3.0.16
- 3.0.17
- 3.5
- 3.5.1
- 3.5.2
- 3.5.3
- 3.5.4
- 3.5.5
- 3.5.6
- 3.5.7
- 3.5.8
- 3.5.9
- 3.5.10
No data.
Red Hat Enterprise Linux 4
firefox-0:3.6.9-1.el4
Fixed · RHSA-2010:0681
Red Hat Enterprise Linux 4
nspr-0:4.8.6-1.el4
Fixed · RHSA-2010:0681
Red Hat Enterprise Linux 4
nss-0:3.12.7-1.el4
Fixed · RHSA-2010:0681
Red Hat Enterprise Linux 5
firefox-0:3.6.9-2.el5
Fixed · RHSA-2010:0681
Red Hat Enterprise Linux 5
nspr-0:4.8.6-1.el5
Fixed · RHSA-2010:0681
Red Hat Enterprise Linux 5
nss-0:3.12.7-2.el5
Fixed · RHSA-2010:0681
Red Hat Enterprise Linux 5
xulrunner-0:1.9.2.9-1.el5
Fixed · RHSA-2010:0681
Red Hat Enterprise Linux 6
firefox
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | firefox-0:3.6.9-1.el4 | Fixed | RHSA-2010:0681 |
| Red Hat Enterprise Linux 4 | nspr-0:4.8.6-1.el4 | Fixed | RHSA-2010:0681 |
| Red Hat Enterprise Linux 4 | nss-0:3.12.7-1.el4 | Fixed | RHSA-2010:0681 |
| Red Hat Enterprise Linux 5 | firefox-0:3.6.9-2.el5 | Fixed | RHSA-2010:0681 |
| Red Hat Enterprise Linux 5 | nspr-0:4.8.6-1.el5 | Fixed | RHSA-2010:0681 |
| Red Hat Enterprise Linux 5 | nss-0:3.12.7-2.el5 | Fixed | RHSA-2010:0681 |
| Red Hat Enterprise Linux 5 | xulrunner-0:1.9.2.9-1.el5 | Fixed | RHSA-2010:0681 |
| Red Hat Enterprise Linux 6 | firefox | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (17)
- http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2010-September/047282.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00002.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/42867 third-party-advisoryx_refsource_SECUNIA
- http://support.avaya.com/css/P8/documents/100112690 x_refsource_CONFIRM
- http://www.debian.org/security/2010/dsa-2106 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:173 vendor-advisoryx_refsource_MANDRIVA
- http://www.mozilla.org/security/announce/2010/mfsa2010-62.html x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/43106 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2010/2323 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0061 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-2769 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=520189 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=630075 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-2769
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12192 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2010-2769
Change history (0)
No recorded changes yet.