CVE-2010-3171
Mozilla Firefox <4.0 - Info Disclosure
Title source: llmDescription
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random number generator that is seeded only once per document object, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack." NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-5913.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Amit Klein · cremoteunix
https://www.exploit-db.com/exploits/34621
References (8)
Scores
EPSS
0.0870
EPSS Percentile
92.5%
Details
CWE
CWE-310
Status
published
Products (7)
mozilla/firefox
3.5.10
mozilla/firefox
3.5.11
mozilla/firefox
3.6.4
mozilla/firefox
3.6.6
mozilla/firefox
3.6.7
mozilla/firefox
3.6.8
mozilla/firefox
4.0 beta1
Published
Sep 15, 2010
Tracked Since
Feb 18, 2026