The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-12-10T18:00:00

Updated: 2024-08-07T03:18:53.052Z

Reserved: 2010-10-05T00:00:00

Link: CVE-2010-3769

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-12-10T19:00:02.390

Modified: 2024-11-21T01:19:33.330

Link: CVE-2010-3769

cve-icon Redhat

No data.