CVE-2010-0159
The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cpp, and unspecified other vectors.
- Affected products
- Firefox, Red Hat, Seamonkey, Suse, Thunderbird
- Mozilla Firefox
- < 3.0.18, 3.5.8
- Mozilla Seamonkey
- < 2.0.3
- Mozilla Thunderbird
- < 3.0.2
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 4.8% (91th percentile)
- NVD status
- Modified
- Published
- 2010-02-21
CVE-2010-0159 at NVD
1 known exploit for CVE-2010-0159
Proof-of-concept code and exploit modules indexed by Sploitus