CVE-2010-4209
Summary
| CVE | CVE-2010-4209 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-11-07 22:00:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.8.1, as used in Bugzilla 3.7.1 through 3.7.3 and 4.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to swfstore/swfstore.swf. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Bugzilla | 3.7.1 | All | All | All |
| Application | Mozilla | Bugzilla | 3.7.2 | All | All | All |
| Application | Mozilla | Bugzilla | 3.7.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1 | All | All | All |
| Application | Yahoo | Yui | 2.8.0 | All | All | All |
| Application | Yahoo | Yui | 2.8.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| YUI 2.8.2 Security Bulletin | af854a3a-2127-422b-91ae-364da2661108 | yuilibrary.com | Patch, Vendor Advisory |
| [SECURITY] Fedora 14 Update: bugzilla-3.6.3-1.fc14 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| [SECURITY] Fedora 13 Update: bugzilla-3.4.9-1.fc13 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| oss-security - Re: CVE request: moodle 1.9.10 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| SecurityTracker.com Archives - Bugzilla Permits Cross-Site Scripting and HTTP Response Splitting Attacks and Discloses Certain Information to Remote Users | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Security Advisory SA42271 - Fedora update for bugzilla - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| YUI Multiple Cross Site Scripting Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 3.2.8, 3.4.8, 3.6.2, and 3.7.3 Security Advisory :: Bugzilla :: bugzilla.org | af854a3a-2127-422b-91ae-364da2661108 | www.bugzilla.org | |
| YUI Multiple Cross-Site Scripting Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:021 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [SECURITY] Fedora 12 Update: bugzilla-3.4.9-1.fc12 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail | OVH- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.