CVE-2010-1199
Firefox 3.5.x-3.5.9 and 3.6.x-3.6.3 - Remote Code Execution via XSLT Node Sorting Integer Overflow
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2010-1199. PoCs published by Abysssec, Martin Barbella.
AI-analyzed exploit summary This exploit generates an XSLT stylesheet and XML file that trigger a heap overflow in Mozilla Firefox 3.6.3 due to excessive nested sorting operations, leading to remote code execution.
Description
Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a node.
Exploits (2)
This exploit generates an XSLT stylesheet and XML file that trigger a heap overflow in Mozilla Firefox 3.6.3 due to excessive nested sorting operations, leading to remote code execution.
This is a vulnerability writeup for CVE-2010-1199, describing an integer overflow vulnerability in Mozilla Firefox, SeaMonkey, and Thunderbird. The writeup references fixed versions and provides a link to a binary exploit but does not contain actual exploit code.