CVE-2010-3177
Mozilla Firefox <3.5.14 & SeaMonkey <2.0.9 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the Gopher parser in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, and SeaMonkey before 2.0.9, allow remote attackers to inject arbitrary web script or HTML via a crafted name of a (1) file or (2) directory on a Gopher server.
References (16)
Scores
EPSS
0.0072
EPSS Percentile
72.3%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/seamonkey
< 2.0.8
mozilla/seamonkey
mozilla/seamonkey
mozilla/seamonkey
mozilla/seamonkey
mozilla/seamonkey
... and 35 more
Timeline
Published
Oct 21, 2010
Tracked Since
Feb 18, 2026