9.3
CVSSv2

CVE-2010-0164

Published: 25/03/2010 Updated: 10/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 prior to 3.6.2 allows remote malicious users to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace animation in which the frames have different bits-per-pixel (bpp) values.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.6

Vendor Advisories

Mozilla Foundation Security Advisory 2010-09 Deleted frame reuse in multipart/x-mixed-replace image Announced March 23, 2010 Reporter regenrecht (via TippingPoint's Zero Day Initiative) Impact Moderate Products Firefox ...