peter bassill · operator
$ cve CVE-2010-2752 JSON

CVE-2010-2752 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 9.8% (pctl 95)

Patch early

A public exploit exists.

Description

Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code by placing many Cascading Style Sheets (CSS) values in an array, related to references to external font resources and an inconsistency between 16-bit and 32-bit integers.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS9.78% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-189
On CISA KEVno
Public exploityes
Published2010-07-30
Last modified2026-06-16

Affected (3)

VendorProduct
mozillafirefox
mozillaseamonkey
mozillathunderbird

Public exploits

SourceTitleDate
exploit-dbMozilla Firefox CSS - font-face Remote Code Execution2010-09-25

References

→ the Explorer  ·  watch your stack  ·  NVD