CVE-2010-3171

Mozilla Firefox <4.0 - Info Disclosure

Title source: llm

Description

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random number generator that is seeded only once per document object, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack." NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-5913.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Amit Klein · cremoteunix
https://www.exploit-db.com/exploits/34621

Scores

EPSS 0.0870
EPSS Percentile 92.5%

Details

CWE
CWE-310
Status published
Products (7)
mozilla/firefox 3.5.10
mozilla/firefox 3.5.11
mozilla/firefox 3.6.4
mozilla/firefox 3.6.6
mozilla/firefox 3.6.7
mozilla/firefox 3.6.8
mozilla/firefox 4.0 beta1
Published Sep 15, 2010
Tracked Since Feb 18, 2026