CVE-2010-0179

Firefox < 3.0.19 and 3.5.x < 3.5.8 - Remote Code Execution via XMLHttpRequestSpy and Chrome Privilege Escalation

Title source: llm
STIX 2.1

Description

Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.

References (25)

Core 25
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/57394
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=504021
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:251
Vendor Advisory x_refsource_confirm
http://support.avaya.com/css/P8/documents/100124650
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39397
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39308
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42818
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6971
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0781
Various Sources vendor-advisory x_refsource_ubuntu
http://ubuntu.com/usn/usn-921-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/39124
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0764
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0030
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:070
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9446
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39243
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0748
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0849
Vendor Advisory vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1023783
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2010/dsa-2027
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/3924
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0332.html

Scores

EPSS 0.0328
EPSS Percentile 86.9%

Details

CWE
CWE-94
Status published
Products (46)
mozilla/firefox 0.1
mozilla/firefox 0.2
mozilla/firefox 0.3
mozilla/firefox 0.4
mozilla/firefox 0.5
mozilla/firefox 0.6
mozilla/firefox 0.6.1
mozilla/firefox 0.7
mozilla/firefox 0.7.1
mozilla/firefox 0.8
... and 36 more
Published Apr 05, 2010
Tracked Since Feb 18, 2026