RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2010-34 Through -47 Multiple Vulnerabilities

BID:41824

Info

RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2010-34 Through -47 Multiple Vulnerabilities

Bugtraq ID: 41824
Class: Unknown
CVE:
Remote: Yes
Local: No
Published: Jul 20 2010 12:00AM
Updated: Jul 26 2010 09:45PM
Credit: Jesse Ruderman, Ehsan Akhgari, Mats Palmgren, Igor Bukanov, Gary Kwong, Tobias Markus, Daniel Holbert, David Anderson, Johnny Stenback, regenrecht, J23, moz_bug_r_a4, Aki Helin, Yosuke Hasegawa, Vladimir Vukicevic, O. Andersen, Chris Evans, and Soroush Dal
Vulnerable: RedHat Enterprise Linux WS 4
RedHat Enterprise Linux WS 3
RedHat Enterprise Linux Optional Productivity Application 5 server
RedHat Enterprise Linux ES 4
RedHat Enterprise Linux ES 3
RedHat Enterprise Linux Desktop Workstation 5 client
RedHat Enterprise Linux Desktop version 4
RedHat Desktop 4.0
RedHat Desktop 3.0
Red Hat Enterprise Linux Desktop 5 client
Red Hat Enterprise Linux AS 4
Red Hat Enterprise Linux AS 3
Red Hat Enterprise Linux 5 Server
Mozilla Thunderbird 3.0.5
Mozilla Thunderbird 3.0.4
Mozilla Thunderbird 3.0.2
Mozilla Thunderbird 3.0.1
Mozilla Thunderbird 3.0
Mozilla SeaMonkey 2.0.5
Mozilla SeaMonkey 2.0.4
Mozilla SeaMonkey 2.0.3
Mozilla SeaMonkey 2.0.2
Mozilla SeaMonkey 2.0.1
Mozilla SeaMonkey 2.0
Mozilla Firefox 3.6.4
Mozilla Firefox 3.6.3
Mozilla Firefox 3.6.2
Mozilla Firefox 3.6.2
Mozilla Firefox 3.5.10
Mozilla Firefox 3.5.9
Mozilla Firefox 3.5.8
Mozilla Firefox 3.5.7
Mozilla Firefox 3.5.6
Mozilla Firefox 3.5.5
Mozilla Firefox 3.5.4
Mozilla Firefox 3.5.3
Mozilla Firefox 3.5.2
Mozilla Firefox 3.5.1
Mozilla Firefox 3.5
Mozilla Firefox 3.6
Not Vulnerable: Mozilla Thunderbird 3.1.1
Mozilla Thunderbird 3.0.6
Mozilla SeaMonkey 2.0.6
Mozilla Firefox 3.6.7
Mozilla Firefox 3.5.11

Discussion

RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2010-34 Through -47 Multiple Vulnerabilities

The Mozilla Foundation has released 14 security advisories specifying vulnerabilities in Mozilla Firefox, Thunderbird, and SeaMonkey.

These vulnerabilities allow attackers to execute arbitrary machine code in the context of the vulnerable application, crash affected applications, elevate privileges, and disclose potentially sensitive information; other attacks may also be possible.

These issues are fixed in:

Firefox 3.6.7
Firefox 3.5.11
Thunderbird 3.0.6
Thunderbird 3.1.1
SeaMonkey 2.0.6

This BID is being retired. The following individual records exist to better document the issues:

41842 Mozilla Firefox and SeaMonkey Plugin Parameters Buffer Overflow Vulnerability
41845 Mozilla Firefox and SeaMonkey 'NodeIterator' Use-After-Free Remote Code Execution Vulnerability
41849 Mozilla Firefox and SeaMonkey DOM Cloning Remote Code Execution Vulnerability
41852 Mozilla Firefox, Thunderbird and SeaMonkey CSS Values Integer Overflow Vulnerability
41853 Mozilla Firefox, Thunderbird, and SeaMonkey 'nsTreeSelection' Remote Code Execution Vulnerability
41859 Mozilla Firefox, Thunderbird, and SeaMonkey CVE-2010-1211 Remote Memory Corruption Vulnerability
41860 Multiple Mozilla Products Script Filename Cross Domain Information Disclosure Vulnerability
41865 Mozilla Firefox, Thunderbird, and SeaMonkey CVE-2010-1212 Remote Memory Corruption Vulnerability
41866 Mozilla Firefox and Thunderbird Character Mapping Security Weakness
41868 Mozilla Firefox and Thunderbird 'SJOW' Privilege Escalation Vulnerability
41871 Multiple Mozilla Products 'importScripts()' Method Cross Domain Information Disclosure Vulnerability
41872 Multiple Mozilla Products CSS Selectors Cross Domain Information Disclosure Vulnerability
41878 Mozilla Firefox and Thunderbird Canvas Element Cross Domain Information Disclosure Vulnerability
41968 Mozilla Firefox and Sea Monkey Location Bar Spoofing Vulnerability

Exploit / POC

RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2010-34 Through -47 Multiple Vulnerabilities

Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

Some of these issues may not require specific exploit code and may be trivial to exploit.

Solution / Fix

RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2010-34 Through -47 Multiple Vulnerabilities

Solution:
New versions of Firefox, SeaMonkey, and Thunderbird are available to address these issues. Most Mozilla applications have self-updating features that may be used to download and install fixes.

Please see the referenced advisories for information on obtaining and applying fixes.

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report