4.3
CVSSv2

CVE-2010-0648

Published: 18/02/2010 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Mozilla Firefox, possibly prior to 3.6, allows remote malicious users to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla firefox 3.5.6

mozilla firefox 3.5.5

mozilla firefox 3.0.8

mozilla firefox 3.0.7

mozilla firefox 3.0.14

mozilla firefox 3.0.13

mozilla firefox 2.0.0.18

mozilla firefox 2.0.0.17

mozilla firefox 2.0.0.10

mozilla firefox 2.0.0.9

mozilla firefox 3.5.4

mozilla firefox 3.5.3

mozilla firefox 3.0.6

mozilla firefox 3.0.5

mozilla firefox 3.0.12

mozilla firefox 3.0.11

mozilla firefox 2.0.0.16

mozilla firefox 2.0.0.15

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.7

mozilla firefox 2.0

mozilla firefox 1.5

mozilla firefox 1.5.0.10

mozilla firefox 1.5.0.6

mozilla firefox 1.5.0.7

mozilla firefox 1.0.7

mozilla firefox 1.0.6

mozilla firefox 3.5.2

mozilla firefox 3.5.1

mozilla firefox 3.0.4

mozilla firefox 3.0.3

mozilla firefox 3.0.10

mozilla firefox 3.0.1

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.13

mozilla firefox 2.0.0.6

mozilla firefox 2.0.0.5

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.5

mozilla firefox 1.5.3

mozilla firefox 1.5.4

mozilla firefox 1.5.8

mozilla firefox 1.0.5

mozilla firefox 1.0.4

mozilla firefox 1.0.3

mozilla firefox 2.0.0.2

mozilla firefox 2.0.0.1

mozilla firefox 1.5.0.12

mozilla firefox 1.5.0.1

mozilla firefox 1.5.0.8

mozilla firefox 1.5.0.9

mozilla firefox 1.5.5

mozilla firefox 1.0.8

mozilla firefox 1.0

mozilla firefox 3.5

mozilla firefox 3.0.9

mozilla firefox 3.0.2

mozilla firefox 3.0.15

mozilla firefox 3.0

mozilla firefox 2.0.0.20

mozilla firefox 2.0.0.19

mozilla firefox 2.0.0.12

mozilla firefox 2.0.0.11

mozilla firefox 2.0.0.4

mozilla firefox 2.0.0.3

mozilla firefox 1.5.0.2

mozilla firefox 1.5.0.3

mozilla firefox 1.5.0.11

mozilla firefox 1.5.1

mozilla firefox 1.5.2

mozilla firefox 1.5.7

mozilla firefox 1.5.6

mozilla firefox 1.0.2

mozilla firefox 1.0.1

Vendor Advisories

Debian Bug report logs - #570743 xulrunner: CVE-2010-0654 cross-origin CSS data theft Package: xulrunner; Maintainer for xulrunner is (unknown); Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Sun, 21 Feb 2010 07:21:01 UTC Severity: important Tags: fixed-upstream, security Found in versions 1923-1, 19 ...