CVE-2010-1214 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 7.6% (pctl 94)
Patch early
A public exploit exists.
Description
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via plugin content with many parameter elements.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 7.59% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-189 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-07-30 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | seamonkey |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mozilla Firefox 3.6.4 - 'Plugin' EnsureCachedAttrParamArrays Remote Code Execution | 2010-09-17 |
| exploit-db | Mozilla Firefox and SeaMonkey Plugin Parameters - Remote Buffer Overflow | 2010-07-20 |
References
- http://www.mozilla.org/security/announce/2010/mfsa2010-37.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=572985
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11685
- http://www.mozilla.org/security/announce/2010/mfsa2010-37.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=572985
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11685
→ the Explorer · watch your stack · NVD