← All CVEs

CVE-2010-0167

high · 9.3

The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (2) the _evaluate function in modules/plugin/base/src/nsNPAPIPlugin.cpp.

9.3
CVSS
10.5%
EPSS (exploit prob.)
96th
EPSS percentile
2010-03-25
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
mozillafirefox3.0
mozillafirefox3.0.1
mozillafirefox3.0.10
mozillafirefox3.0.11
mozillafirefox3.0.12
mozillafirefox3.0.13
mozillafirefox3.0.14
mozillafirefox3.0.15
mozillafirefox3.0.16
mozillafirefox3.0.17
mozillafirefox3.5
mozillafirefox3.5.1
mozillafirefox3.5.2
mozillafirefox3.5.3
mozillafirefox3.5.4
mozillafirefox3.5.5
mozillafirefox3.5.6
mozillafirefox3.5.7
mozillafirefox3.6
mozillaseamonkey<= 2.0.2
mozillaseamonkey1.1
mozillaseamonkey1.1
mozillaseamonkey1.1
mozillaseamonkey1.1.1
mozillaseamonkey1.1.2
mozillaseamonkey1.1.3
mozillaseamonkey1.1.4
mozillaseamonkey1.1.5
mozillaseamonkey1.1.5
mozillaseamonkey1.1.6
mozillaseamonkey1.1.7
mozillaseamonkey1.1.8
mozillaseamonkey1.1.9
mozillaseamonkey1.1.10
mozillaseamonkey1.1.11
mozillaseamonkey1.1.12
mozillaseamonkey1.1.13
mozillaseamonkey1.1.14
mozillaseamonkey1.1.15
mozillaseamonkey1.1.16

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-0167