The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the browser's font and other CSS attributes, and potentially disrupt rendering of a web page, by forcing the browser to perform this erroneous stylesheet caching.
Advisories
Source ID Title
EUVD EUVD EUVD-2010-0200 The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the browser's font and other CSS attributes, and potentially disrupt rendering of a web page, by forcing the browser to perform this erroneous stylesheet caching.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T00:37:54.100Z

Reserved: 2010-01-06T00:00:00

Link: CVE-2010-0169

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2010-03-25T21:00:00.517

Modified: 2025-04-11T00:51:21.963

Link: CVE-2010-0169

cve-icon Redhat

Severity : Low

Publid Date: 2010-03-23T00:00:00Z

Links: CVE-2010-0169 - Bugzilla

cve-icon OpenCVE Enrichment

No data.