CVE-2010-0160
Summary
| CVE | CVE-2010-0160 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-02-22 13:00:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 3.0 | All | All | All |
| Application | Mozilla | Firefox | 3.0.1 | All | All | All |
| Application | Mozilla | Firefox | 3.0.10 | All | All | All |
| Application | Mozilla | Firefox | 3.0.11 | All | All | All |
| Application | Mozilla | Firefox | 3.0.12 | All | All | All |
| Application | Mozilla | Firefox | 3.0.13 | All | All | All |
| Application | Mozilla | Firefox | 3.0.14 | All | All | All |
| Application | Mozilla | Firefox | 3.0.15 | All | All | All |
| Application | Mozilla | Firefox | 3.0.16 | All | All | All |
| Application | Mozilla | Firefox | 3.0.2 | All | All | All |
| Application | Mozilla | Firefox | 3.0.3 | All | All | All |
| Application | Mozilla | Firefox | 3.0.4 | All | All | All |
| Application | Mozilla | Firefox | 3.0.5 | All | All | All |
| Application | Mozilla | Firefox | 3.0.6 | All | All | All |
| Application | Mozilla | Firefox | 3.0.7 | All | All | All |
| Application | Mozilla | Firefox | 3.0.8 | All | All | All |
| Application | Mozilla | Firefox | 3.0.9 | All | All | All |
| Application | Mozilla | Firefox | 3.5 | All | All | All |
| Application | Mozilla | Firefox | 3.5.1 | All | All | All |
| Application | Mozilla | Firefox | 3.5.2 | All | All | All |
| Application | Mozilla | Firefox | 3.5.3 | All | All | All |
| Application | Mozilla | Firefox | 3.5.4 | All | All | All |
| Application | Mozilla | Firefox | 3.5.5 | All | All | All |
| Application | Mozilla | Firefox | 3.5.6 | All | All | All |
| Application | Mozilla | Firefox | 3.5.7 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | alpha | All | All |
| Application | Mozilla | Seamonkey | 1.0 | beta | All | All |
| Application | Mozilla | Seamonkey | 1.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.2 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.3 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.4 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.5 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.6 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.7 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.8 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.9 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1 | alpha | All | All |
| Application | Mozilla | Seamonkey | 1.1 | beta | All | All |
| Application | Mozilla | Seamonkey | 1.1.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.10 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.11 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.12 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.13 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.14 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.15 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.16 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.17 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.2 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.3 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.4 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.5 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.6 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.7 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.8 | All | All | All |
| Application | Mozilla | Seamonkey | 1.1.9 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_2 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_3 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | beta_1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | beta_2 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | rc1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | rc2 | All | All |
| Application | Mozilla | Seamonkey | 2.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| [SECURITY] Fedora 12 Update: galeon-2.0.7-20.fc12 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| USN-895-1: Firefox 3.0 and Xulrunner 1.9 vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Support / Security / Advisories / / MDVSA-2010:042 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Debian -- Security Information -- DSA-1999-1 xulrunner | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [SECURITY] Fedora 12 Update: seamonkey-2.0.3-1.fc12 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| 531222 – Using SSM off main thread | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| USN-896-1: Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Mozilla Firefox Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SUSE update for MozillaFirefox and seamonkey - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| 534051 – Workers: Don't change the global object while GC is running | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| [security-announce] SUSE Security Announcement: Mozilla Firefox (SUSE-SA | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [SECURITY] Fedora 11 Update: epiphany-extensions-2.26.1-10.fc11 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| MFSA 2010-02: Web Worker Array Handling Heap Corruption Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| 533000 – (CVE-2010-0160) Web Worker Array Handling Heap Corruption Vulnerability (ZDI-CAN-624) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.