← Back

CVE-2010-1212

nvd nist
Published: Jul 30, 2010Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) propagation of deep aborts in the TraceRecorder::record_JSOP_BINDNAME function, (2) depth handling in the TraceRecorder::record_JSOP_GETELEM function, and (3) tracing of out-of-range arguments in the TraceRecorder::record_JSOP_ARGSUB function.

Affected (6)

2 products
Firefox
Thunderbird
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 3.6.1
Version 3.6.2
Version 3.6.3
Version 3.6.4
Version 3.6.6
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.1

Timeline

No history available yet.