← Back

CVE-2010-0654

nvd nist
Published: Feb 18, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.

Affected (71)

3 products
Firefox
Seamonkey
Thunderbird
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 3.5.10
Version 3.5.1
Version 3.5.2
Version 3.5.3
Version 3.5.4
Version 3.5.5
Version 3.5.6
Version 3.5.7
Version 3.5.9
Version 3.6.1
Version 3.6.2
Version 3.6.3
Version 3.6.4
Version 3.6.6
Configuration B
51 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Up to 2.0.5
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.0.5
Version 1.0.6
Version 1.0.7
Version 1.0.8
Version 1.0.9
Version 1.0
Version 1.0 alpha
Version 1.0 beta
Version 1.1.10
Version 1.1.11
Version 1.1.12
Version 1.1.13
Version 1.1.14
Version 1.1.15
Version 1.1.16
Version 1.1.17
Version 1.1.18
Version 1.1.19
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 1.1.6
Version 1.1.7
Version 1.1.8
Version 1.1.9
Version 1.1
Version 1.1 alpha
Version 1.1 beta
Version 1.5.0.10
Version 1.5.0.8
Version 1.5.0.9
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0
Version 2.0 alpha_1
Version 2.0 alpha_2
Version 2.0 alpha_3
Version 2.0 beta_1
Version 2.0 beta_2
Version 2.0 rc1
Version 2.0 rc2
Version 2.0a1pre
Configuration C
6 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0.4
Version 3.0.5
Version 3.1

Timeline

No history available yet.