{"api_version":"1","generated_at":"2026-07-24T19:14:37+00:00","cve":"CVE-2010-0172","urls":{"html":"https://cve.report/CVE-2010-0172","api":"https://cve.report/api/cve/CVE-2010-0172.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-0172","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-0172"},"summary":{"title":"CVE-2010-0172","description":"toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6 before 3.6.2 does not properly handle concurrent authorization requests from multiple web sites, which might allow remote web servers to spoof an authorization dialog and capture credentials by demanding HTTP authentication in opportunistic circumstances.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-03-25 21:00:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=537862","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=537862","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"537862 – (CVE-2010-0172) asyncAuthPrompt can attach to wrong DOM window.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8281","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8281","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:070","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:070","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisories | Mandriva Linux","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2010/mfsa2010-15.html","name":"http://www.mozilla.org/security/announce/2010/mfsa2010-15.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"MFSA 2010-15: Asynchronous Auth Prompt attaches to wrong window","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/38918","name":"http://www.securityfocus.com/bid/38918","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"RETIRED: Mozilla Firefox Thunderbird and Seamonkey MFSA 2010-09 through -15 Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2010/0692","name":"http://www.vupen.com/english/advisories/2010/0692","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-0172","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-0172","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"172","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"3.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T00:37:54.085Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"38918","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/38918"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/2010/mfsa2010-15.html"},{"name":"oval:org.mitre.oval:def:8281","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8281"},{"name":"MDVSA-2010:070","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:070"},{"name":"ADV-2010-0692","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0692"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=537862"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-03-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6 before 3.6.2 does not properly handle concurrent authorization requests from multiple web sites, which might allow remote web servers to spoof an authorization dialog and capture credentials by demanding HTTP authentication in opportunistic circumstances."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"38918","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/38918"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/2010/mfsa2010-15.html"},{"name":"oval:org.mitre.oval:def:8281","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8281"},{"name":"MDVSA-2010:070","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:070"},{"name":"ADV-2010-0692","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0692"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=537862"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-0172","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6 before 3.6.2 does not properly handle concurrent authorization requests from multiple web sites, which might allow remote web servers to spoof an authorization dialog and capture credentials by demanding HTTP authentication in opportunistic circumstances."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"38918","refsource":"BID","url":"http://www.securityfocus.com/bid/38918"},{"name":"http://www.mozilla.org/security/announce/2010/mfsa2010-15.html","refsource":"CONFIRM","url":"http://www.mozilla.org/security/announce/2010/mfsa2010-15.html"},{"name":"oval:org.mitre.oval:def:8281","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8281"},{"name":"MDVSA-2010:070","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:070"},{"name":"ADV-2010-0692","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/0692"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=537862","refsource":"CONFIRM","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=537862"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-0172","datePublished":"2010-03-25T20:31:00.000Z","dateReserved":"2010-01-06T00:00:00.000Z","dateUpdated":"2024-08-07T00:37:54.085Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-03-25 21:00:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:3.6:*:*:*:*:*:*:*","matchCriteriaId":"F3782354-7EB7-49D2-B240-1871F6CB84C7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"172","Ordinal":"1","Title":"CVE-2010-0172","CVE":"CVE-2010-0172","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"172","Ordinal":"1","NoteData":"toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6 before 3.6.2 does not properly handle concurrent authorization requests from multiple web sites, which might allow remote web servers to spoof an authorization dialog and capture credentials by demanding HTTP authentication in opportunistic circumstances.","Type":"Description","Title":"CVE-2010-0172"},{"CveYear":"2010","CveId":"172","Ordinal":"2","NoteData":"2010-03-25","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"172","Ordinal":"3","NoteData":"2017-09-18","Type":"Other","Title":"Modified"}]}}}