Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2010-1209

EPSS 2.21% · P85
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2010-1209

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Use-after-free vulnerability in the NodeIterator implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via a crafted NodeFilter that detaches DOM nodes, related to the NodeIterator interface and a javascript callback.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Mozilla Firefox和SeaMonkey NodeIterator实现释放后使用漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。Mozilla SeaMonkey是美国Mozilla基金会开发的一个免费、开源以及跨平台的网络套装软件。 Mozilla Firefox 3.5.11之前的3.5.x版本和3.6.7之前的3.6.x版本,以及SeaMonkey 2.0.6之前版本的NodeIterator接口实现中存在释放后使用漏洞。用户可以创建特制的NodeFilter,在遍历时会从DOM树分离节点。使用了已分离且之后被删除的节点就可能导致执行受控的内
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2010-1209

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-1209

Please Login to view more intelligence information

Same Patch Batch · n/a · 2010-07-30 · 40 CVEs total

CVE-2010-2917AJ Square AJ Article 'index.php'多个跨站脚本攻击漏洞
CVE-2010-1792Apple Safari WebKit正则表达式缓冲区溢出漏洞
CVE-2010-1793Apple Safari WebKit多个释放后使用漏洞
CVE-2010-1796Apple Safari个人地址簿自动填充功能信息泄露漏洞
CVE-2010-2751Mozilla Firefox history.back()和history.forward()方式地址栏欺骗漏洞
CVE-2010-2752Mozilla Firefox/Thunderbird/SeaMonkey nsCSSValue::Array索引整数溢出漏洞
CVE-2010-2753Mozilla Firefox/Thunderbird/SeaMonkey TreeSelection悬停指针远程代码执行漏洞
CVE-2010-2914Nessus Nessus Web Server插件'nessusd_www_server.nbin'跨站脚本攻击漏洞
CVE-2010-2915AJ Square AJ HYIP PRIME 'welcome.php'SQL注入漏洞
CVE-2010-2916AJ Square AJ HYIP MERIDIAN 'news.php'SQL注入漏洞
CVE-2010-1791Apple Safari WebKit整数符号错误漏洞
CVE-2010-2918Visocrea Visites组件SQL注入漏洞
CVE-2010-2919Joomlaxt StaticXT SQL注入漏洞
CVE-2010-2920Foobla Suggestions组件路径遍历漏洞
CVE-2010-2921Photoindochina Golf Course Guide组件SQL注入漏洞
CVE-2010-2922AKY Blog 'default.asp'SQL注入漏洞
CVE-2010-2923Prasanna YouTube组件SQL注入漏洞
CVE-2010-2924Silvercover myLinksDump插件 'myLDlinker.php'SQL注入漏洞
CVE-2010-2925Open Freeway 'index.php' ecPath SQL注入漏洞
CVE-2010-2926Solucija sNews 'index.php'SQL注入漏洞

Showing top 20 of 40 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-1209

No comments yet


Leave a comment