CVE-2010-3131
CVE-2010-3131
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .htm, .html, .jtx, .mfp, or .eml file.
Productos afectados
n/a · n/aPoCs públicas encontradas — 4
cve_referencewww.exploit-db.com/exploits/14730no verificadocve_referencewww.exploit-db.com/exploits/14783no verificadoexploitdbwww.exploit-db.com/exploits/14730no verificadoexploitdbwww.exploit-db.com/exploits/14783no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00002.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=579593http://secunia.com/advisories/41095http://secunia.com/advisories/41168https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12143http://www.exploit-db.com/exploits/14730http://www.exploit-db.com/exploits/14783http://www.mozilla.org/security/announce/2010/mfsa2010-52.htmlhttp://www.securityfocus.com/archive/1/513324/100/0/threadedhttp://www.vupen.com/english/advisories/2010/2169http://www.vupen.com/english/advisories/2010/2201http://www.vupen.com/english/advisories/2010/2323