CVE-2010-1207
30.07.2010, 20:30
Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node deletion.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mozilla | firefox | 𝑥 ≤ 3.6.6 |
| mozilla | firefox | 3.6 |
| mozilla | firefox | 3.6.2 |
| mozilla | firefox | 3.6.3 |
| mozilla | firefox | 3.6.4 |
| mozilla | thunderbird | 𝑥 ≤ 3.1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| firefox |
| ||||||||||
| firefox-3.0 |
| ||||||||||
| firefox-3.5 |
| ||||||||||
| xulrunner-1.9.2 |
|
Common Weakness Enumeration
References