Candidate: CVE-2010-0171 PublicDate: 2010-03-25 21:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0171 http://www.mozilla.org/security/announce/2010/mfsa2010-12.html Description: Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allow remote attackers to perform cross-origin keystroke capture, and possibly conduct cross-site scripting (XSS) attacks, by using the addEventListener and setTimeout functions in conjunction with a wrapped object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-3736. Ubuntu-Description: Notes: Bugs: https://bugzilla.mozilla.org/show_bug.cgi?id=531364 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_firefox: upstream_firefox: released (3.6.2) dapper_firefox: ignored (reached end-of-life) hardy_firefox: not-affected intrepid_firefox: DNE jaunty_firefox: DNE karmic_firefox: DNE lucid_firefox: released (3.6.3+nobinonly-0ubuntu2) devel_firefox: released (3.6.3+nobinonly-0ubuntu2) Patches_xulrunner-1.9: upstream_xulrunner-1.9: released (1.9.0.19) dapper_xulrunner-1.9: DNE hardy_xulrunner-1.9: released (1.9.0.19+nobinonly-0ubuntu0.8.04.1) intrepid_xulrunner-1.9: released (1.9.0.19+nobinonly-0ubuntu0.8.10.1) jaunty_xulrunner-1.9: released (1.9.0.19+nobinonly-0ubuntu0.9.04.1) karmic_xulrunner-1.9: DNE lucid_xulrunner-1.9: DNE devel_xulrunner-1.9: DNE Patches_xulrunner-1.9.1: upstream_xulrunner-1.9.1: released (1.9.1.9) dapper_xulrunner-1.9.1: DNE hardy_xulrunner-1.9.1: DNE intrepid_xulrunner-1.9.1: DNE jaunty_xulrunner-1.9.1: released (1.9.1.9+nobinonly-0ubuntu0.9.04.1) karmic_xulrunner-1.9.1: released (1.9.1.9+nobinonly-0ubuntu0.9.10.1) lucid_xulrunner-1.9.1: DNE devel_xulrunner-1.9.1: DNE Patches_seamonkey: upstream_seamonkey: released (2.0.3) dapper_seamonkey: DNE hardy_seamonkey: released (2.0.8+build1+nobinonly-0ubuntu0.8.04.1) intrepid_seamonkey: needed (reached end-of-life) jaunty_seamonkey: released (2.0.8+build1+nobinonly-0ubuntu0.9.04.1) karmic_seamonkey: released (2.0.8+build1+nobinonly-0ubuntu0.9.10.1) lucid_seamonkey: released (2.0.8+build1+nobinonly-0ubuntu0.10.04.1) devel_seamonkey: not-affected (2.0.4+nobinonly-0ubuntu1) Patches_thunderbird: Priority_thunderbird: low upstream_thunderbird: released (3.0.2) dapper_thunderbird: DNE hardy_thunderbird: not-affected intrepid_thunderbird: not-affected jaunty_thunderbird: not-affected karmic_thunderbird: not-affected lucid_thunderbird: released (3.0.4+nobinonly-0ubuntu1) devel_thunderbird: released (3.0.4+nobinonly-0ubuntu1)