Back

HIGH

Mozilla crash and remote code execution using HTML tags inside a XUL tree (MFSA 2010-77)

Published Dec 10, 2010

Description

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly calculate index values for certain child content in a XUL tree, which allows remote attackers to execute arbitrary code via vectors involving a DIV element within a treechildren element.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (24)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 10, 2010
Updated Aug 7, 2024
Reserved Oct 5, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Dec 9, 2010