CVE-2010-1121
Last modified
CVE-2010-1121 is a vulnerability of currently unknown severity. Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote attackers to conduct use-after-free attacks and execute arbitrary code via unspecified vectors involving improper interaction with garbage collection, as demonstrated by Nils during a Pwn2Own competition at CanSecWest 2010.. EPSS estimates a 5.73% chance of exploitation in the next 30 days.
Description
Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote attackers to conduct use-after-free attacks and execute arbitrary code via unspecified vectors involving improper interaction with garbage collection, as demonstrated by Nils during a Pwn2Own competition at CanSecWest 2010.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 3.6 |
| Mozilla | Firefox | 3.6.1 |
| Mozilla | Firefox | 3.6.2 |
References
- http://secunia.com/advisories/40323Vendor Advisory
- http://secunia.com/advisories/40326Vendor Advisory
- http://secunia.com/advisories/40401Vendor Advisory
- http://secunia.com/advisories/40481Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1557Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1640Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1773Vendor Advisory
- http://secunia.com/advisories/40323Vendor Advisory
- http://secunia.com/advisories/40326Vendor Advisory
- http://secunia.com/advisories/40401Vendor Advisory
- http://secunia.com/advisories/40481Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1557Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1640Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1773Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-1121?
How severe is CVE-2010-1121?
How do I fix CVE-2010-1121?
Are you affected by CVE-2010-1121?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
