CVE-2010-2752 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 9.8% (pctl 95)
Patch early
A public exploit exists.
Description
Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code by placing many Cascading Style Sheets (CSS) values in an array, related to references to external font resources and an inconsistency between 16-bit and 32-bit integers.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 9.78% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-189 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-07-30 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | seamonkey |
| mozilla | thunderbird |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mozilla Firefox CSS - font-face Remote Code Execution | 2010-09-25 |
References
- http://www.mozilla.org/security/announce/2010/mfsa2010-39.html
- http://www.securityfocus.com/archive/1/512514
- http://www.securityfocus.com/bid/41852
- http://www.zerodayinitiative.com/advisories/ZDI-10-133/
- https://bugzilla.mozilla.org/show_bug.cgi?id=574059
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11680
- http://www.mozilla.org/security/announce/2010/mfsa2010-39.html
- http://www.securityfocus.com/archive/1/512514
- http://www.securityfocus.com/bid/41852
- http://www.zerodayinitiative.com/advisories/ZDI-10-133/
- https://bugzilla.mozilla.org/show_bug.cgi?id=574059
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11680
→ the Explorer · watch your stack · NVD