Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.
References
Link Resource
http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038367.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038378.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038406.html
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
http://secunia.com/advisories/38566 Vendor Advisory
http://secunia.com/advisories/39117 Vendor Advisory
http://secunia.com/advisories/39136 Vendor Advisory
http://secunia.com/advisories/39204 Vendor Advisory
http://secunia.com/advisories/39240 Vendor Advisory
http://secunia.com/advisories/39242 Vendor Advisory
http://secunia.com/advisories/39243 Vendor Advisory
http://secunia.com/advisories/39308
http://secunia.com/advisories/39397
http://securitytracker.com/id?1023780
http://securitytracker.com/id?1023782
http://ubuntu.com/usn/usn-921-1
http://www.debian.org/security/2010/dsa-2027
http://www.mandriva.com/security/advisories?name=MDVSA-2010:070
http://www.mozilla.org/security/announce/2010/mfsa2010-17.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0332.html
http://www.redhat.com/support/errata/RHSA-2010-0333.html
http://www.securityfocus.com/archive/1/510542/100/0/threaded
http://www.vupen.com/english/advisories/2010/0748 Vendor Advisory
http://www.vupen.com/english/advisories/2010/0764 Vendor Advisory
http://www.vupen.com/english/advisories/2010/0765 Vendor Advisory
http://www.vupen.com/english/advisories/2010/0781
http://www.vupen.com/english/advisories/2010/0790
http://www.vupen.com/english/advisories/2010/0849
http://www.zerodayinitiative.com/advisories/ZDI-10-050
https://bugzilla.mozilla.org/show_bug.cgi?id=375928
https://bugzilla.mozilla.org/show_bug.cgi?id=540100
https://exchange.xforce.ibmcloud.com/vulnerabilities/57390
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7546
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9834
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2010-04-05T17:00:00

Updated: 2018-10-10T18:57:01

Reserved: 2010-01-06T00:00:00


Link: CVE-2010-0175

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2010-04-05T17:30:00.407

Modified: 2018-10-30T16:25:58.530


Link: CVE-2010-0175

JSON object: View

cve-icon Redhat Information

No data.

CWE