← Back

CVE-2010-3399

nvd nist
Published: Sep 15, 2010Modified: Apr 29, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a context pointer in conjunction with its successor pointer for seeding of a random number generator, which makes it easier for remote attackers to guess the seed value via a brute-force attack, a different vulnerability than CVE-2010-3171.

Affected (7)

Products: Mozilla: Firefox
1 product
Firefox
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 3.5.10
Version 3.5.11
Version 3.6.4
Version 3.6.6
Version 3.6.7
Version 3.6.8
Version 4.0 beta1

Related CWEs

References (16)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.