peter bassill · operator
$ cve CVE-2010-0166 JSON

CVE-2010-0166 EXPLOIT

5.1
MEDIUM · CVSS 2.0 · EPSS 6.9% (pctl 94)

Patch early

A public exploit exists.

Description

The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when the Core Text API is used, does not properly perform certain deletions, which allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via an HTML document containing invisible Unicode characters, as demonstrated by the U+FEFF, U+FFF9, U+FFFA, and U+FFFB characters.

Scoring

CVSS5.1 (MEDIUM, v2.0)
VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS6.89% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2010-03-25
Last modified2026-06-16

Affected (2)

VendorProduct
applemac os x
mozillafirefox

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD