CVE Database
/

CVE-2010-0166

Back to search

CVE-2010-0166

Published: Mar 25, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when the Core Text API is used, does not properly perform certain deletions, which allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via an HTML document containing invisible Unicode characters, as demonstrated by the U+FEFF, U+FFF9, U+FFFA, and U+FFFB characters.

VendorProductVersions

n/a

n/a

affected
n/a

References

38918
vdb-entry
x_refsource_BID
oval:org.mitre.oval:def:14182
vdb-entry
signature
x_refsource_OVAL
ADV-2010-0692
vdb-entry
x_refsource_VUPEN
38943
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now