CVE-2010-2768
Mozilla Firefox <3.5.12 & <3.6.9 - XSS
Title source: llmDescription
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms via UTF-7 encoding.
References (14)
Scores
EPSS
0.0128
EPSS Percentile
79.4%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/seamonkey
< 2.0.6
mozilla/seamonkey
mozilla/seamonkey
mozilla/seamonkey
mozilla/seamonkey
mozilla/seamonkey
mozilla/seamonkey
mozilla/seamonkey
... and 35 more
Timeline
Published
Sep 09, 2010
Tracked Since
Feb 18, 2026