The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2010-12-10T18:00:00

Updated: 2017-09-18T12:57:01

Reserved: 2010-10-05T00:00:00


Link: CVE-2010-3769

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2010-12-10T19:00:02.390

Modified: 2017-09-19T01:31:33.190


Link: CVE-2010-3769

JSON object: View

cve-icon Redhat Information

No data.

CWE