CVE-2010-1121
25.03.2010, 21:00
Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote attackers to conduct use-after-free attacks and execute arbitrary code via unspecified vectors involving improper interaction with garbage collection, as demonstrated by Nils during a Pwn2Own competition at CanSecWest 2010.
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 3.6 |
mozilla | firefox | 3.6.1 |
mozilla | firefox | 3.6.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||
thunderbird |
| ||||||||||||
xulrunner-1.9 |
| ||||||||||||
xulrunner-1.9.1 |
| ||||||||||||
xulrunner-1.9.2 |
|
References