Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms via UTF-7 encoding.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-09-09T18:00:00

Updated: 2024-08-07T02:46:48.602Z

Reserved: 2010-07-14T00:00:00

Link: CVE-2010-2768

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-09-09T19:00:02.530

Modified: 2017-09-19T01:31:07.720

Link: CVE-2010-2768

cve-icon Redhat

Severity : Moderate

Publid Date: 2010-09-07T00:00:00Z

Links: CVE-2010-2768 - Bugzilla