9.3
CVSSv2

CVE-2010-3768

Published: 10/12/2010 Updated: 19/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Mozilla Firefox prior to 3.5.16 and 3.6.x prior to 3.6.13, Thunderbird prior to 3.0.11 and 3.1.x prior to 3.1.7, and SeaMonkey prior to 2.0.11 do not properly validate downloadable fonts before use within an operating system's font implementation, which allows remote malicious users to execute arbitrary code via vectors related to @font-face Cascading Style Sheets (CSS) rules.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.6.10

mozilla firefox 3.6.9

mozilla firefox 3.6.4

mozilla firefox 3.6.2

mozilla firefox 3.6.3

mozilla firefox 3.6.11

mozilla firefox 3.6.12

mozilla firefox 3.6.6

mozilla firefox 3.6.7

mozilla firefox 3.6

mozilla firefox 3.6.8

mozilla seamonkey 1.0.3

mozilla seamonkey 1.0.4

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.10

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.17

mozilla seamonkey 1.1.6

mozilla seamonkey 1.1.7

mozilla seamonkey 1.5.0.9

mozilla seamonkey 2.0

mozilla seamonkey 2.0.9

mozilla seamonkey

mozilla seamonkey 1.0.5

mozilla seamonkey 1.0.6

mozilla seamonkey 1.0

mozilla seamonkey 1.1.18

mozilla seamonkey 1.1.19

mozilla seamonkey 1.1.8

mozilla seamonkey 1.1.9

mozilla seamonkey 2.0.1

mozilla seamonkey 2.0.2

mozilla seamonkey 2.0.3

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0.8

mozilla seamonkey 1.1.11

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.13

mozilla seamonkey 1.1.2

mozilla seamonkey 1.1.3

mozilla seamonkey 1.1

mozilla seamonkey 2.0.4

mozilla seamonkey 2.0.5

mozilla seamonkey 2.0.6

mozilla seamonkey 1.0.1

mozilla seamonkey 1.0.2

mozilla seamonkey 1.0.9

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.15

mozilla seamonkey 1.1.4

mozilla seamonkey 1.1.5

mozilla seamonkey 1.5.0.10

mozilla seamonkey 1.5.0.8

mozilla seamonkey 2.0.7

mozilla seamonkey 2.0.8

mozilla firefox 3.5.6

mozilla firefox 3.5.7

mozilla firefox 3.0.14

mozilla firefox 3.0.13

mozilla firefox 3.0.6

mozilla firefox 3.0.5

mozilla firefox 3.5.1

mozilla firefox 3.5.10

mozilla firefox 3.5.9

mozilla firefox 3.5.8

mozilla firefox 3.0.12

mozilla firefox 3.0.11

mozilla firefox 3.0.4

mozilla firefox 3.0.3

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.9

mozilla firefox 2.0.0.7

mozilla firefox 2.0

mozilla firefox 2.0.0.1

mozilla firefox 1.5

mozilla firefox 3.5.2

mozilla firefox 3.5.3

mozilla firefox 3.5

mozilla firefox 3.0.17

mozilla firefox 3.0.10

mozilla firefox 3.0.9

mozilla firefox 3.0.2

mozilla firefox 3.0.1

mozilla firefox 2.0.0.17

mozilla firefox 2.0.0.10

mozilla firefox 2.0.0.18

mozilla firefox 2.0.0.6

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.5

mozilla firefox 1.5.3

mozilla firefox 1.5.4

mozilla firefox 1.5.8

mozilla firefox 1.0.2

mozilla firefox 1.0.5

mozilla firefox 1.0.4

mozilla firefox 3.5.13

mozilla firefox 3.5.14

mozilla firefox 1.5.0.10

mozilla firefox 1.5.0.6

mozilla firefox 1.5.0.7

mozilla firefox 1.0

mozilla firefox 1.0.3

mozilla firefox 3.5.11

mozilla firefox 3.5.12

mozilla firefox 2.0.0.12

mozilla firefox 2.0.0.19

mozilla firefox 2.0.0.20

mozilla firefox 2.0.0.15

mozilla firefox 2.0.0.13

mozilla firefox 2.0.0.3

mozilla firefox 2.0.0.2

mozilla firefox 1.5.0.12

mozilla firefox 1.5.0.1

mozilla firefox 1.5.0.8

mozilla firefox 1.5.0.9

mozilla firefox 1.5.5

mozilla firefox 1.0.1

mozilla firefox 1.0.8

mozilla firefox 3.5.4

mozilla firefox 3.5.5

mozilla firefox 3.0.16

mozilla firefox 3.0.15

mozilla firefox 3.0.8

mozilla firefox 3.0.7

mozilla firefox 3.0

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.16

mozilla firefox 2.0.0.11

mozilla firefox 2.0.0.5

mozilla firefox 2.0.0.4

mozilla firefox 1.5.0.2

mozilla firefox 1.5.0.3

mozilla firefox 1.5.0.11

mozilla firefox 1.5.1

mozilla firefox 1.5.2

mozilla firefox 1.5.7

mozilla firefox 1.5.6

mozilla firefox 1.0.7

mozilla firefox 1.0.6

mozilla firefox

mozilla thunderbird 3.0.2

mozilla thunderbird 3.0.3

mozilla thunderbird 2.0.0.0

mozilla thunderbird 2.0.0.3

mozilla thunderbird 2.0.0.2

mozilla thunderbird 2.0

mozilla thunderbird 2.0.0.21

mozilla thunderbird 2.0.0.6

mozilla thunderbird 2.0.0.18

mozilla thunderbird 1.5

mozilla thunderbird 1.0.2

mozilla thunderbird 1.5.0.7

mozilla thunderbird 1.5.0.1

mozilla thunderbird 1.7.3

mozilla thunderbird 1.5.0.13

mozilla thunderbird 0.7.1

mozilla thunderbird 0.8

mozilla thunderbird 0.4

mozilla thunderbird 3.0

mozilla thunderbird 3.0.5

mozilla thunderbird 3.0.4

mozilla thunderbird 2.0.0.1

mozilla thunderbird 2.0.0.8

mozilla thunderbird 2.0.0.7

mozilla thunderbird 2.0.0.9

mozilla thunderbird 2.0.0.23

mozilla thunderbird 1.0.6

mozilla thunderbird 1.0.7

mozilla thunderbird 1.0.8

mozilla thunderbird 1.5.0.4

mozilla thunderbird 1.5.0.6

mozilla thunderbird 1.5.0.5

mozilla thunderbird 1.7.1

mozilla thunderbird 0.7.3

mozilla thunderbird 0.7

mozilla thunderbird 0.6

mozilla thunderbird 0.3

mozilla thunderbird 3.0.9

mozilla thunderbird

mozilla thunderbird 3.0.7

mozilla thunderbird 3.0.6

mozilla thunderbird 2.0.0.5

mozilla thunderbird 2.0.0.4

mozilla thunderbird 2.0.0.17

mozilla thunderbird 2.0.0.22

mozilla thunderbird 1.5.2

mozilla thunderbird 1.5.1

mozilla thunderbird 1.0.5

mozilla thunderbird 1.5.0.3

mozilla thunderbird 1.5.0.2

mozilla thunderbird 1.5.0.12

mozilla thunderbird 1.0

mozilla thunderbird 1.0.1

mozilla thunderbird 0.7.2

mozilla thunderbird 0.2

mozilla thunderbird 0.5

mozilla thunderbird 3.0.1

mozilla thunderbird 3.0.8

mozilla thunderbird 2.0.0.19

mozilla thunderbird 2.0.0.12

mozilla thunderbird 2.0.0.16

mozilla thunderbird 2.0.0.14

mozilla thunderbird 1.5.0.9

mozilla thunderbird 1.5.0.8

mozilla thunderbird 1.0.3

mozilla thunderbird 1.0.4

mozilla thunderbird 1.5.0.10

mozilla thunderbird 1.5.0.11

mozilla thunderbird 1.5.0.14

mozilla thunderbird 0.9

mozilla thunderbird 0.1

mozilla thunderbird 3.1.6

mozilla thunderbird 3.1.4

mozilla thunderbird 3.1.5

mozilla thunderbird 3.1.2

mozilla thunderbird 3.1.3

mozilla thunderbird 3.1

mozilla thunderbird 3.1.1

Vendor Advisories

Thunderbird could be made to crash or run programs as your login if it opened a specially crafted file ...
Firefox could be made to crash or run programs as your login if it opened a specially crafted website ...
Mozilla Foundation Security Advisory 2010-78 Add support for OTS font sanitizer Announced December 9, 2010 Reporter Marc Schoenefeld, Christoph Diehl Impact Critical Products Firefox, SeaMonkey, Thunderbird Fixed in ...