CVE-2010-3131
CVE-2010-3131
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .htm, .html, .jtx, .mfp, or .eml file.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 4
cve_referencewww.exploit-db.com/exploits/14730não verificadocve_referencewww.exploit-db.com/exploits/14783não verificadoexploitdbwww.exploit-db.com/exploits/14730não verificadoexploitdbwww.exploit-db.com/exploits/14783não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00002.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=579593http://secunia.com/advisories/41095http://secunia.com/advisories/41168https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12143http://www.exploit-db.com/exploits/14730http://www.exploit-db.com/exploits/14783http://www.mozilla.org/security/announce/2010/mfsa2010-52.htmlhttp://www.securityfocus.com/archive/1/513324/100/0/threadedhttp://www.vupen.com/english/advisories/2010/2169http://www.vupen.com/english/advisories/2010/2201http://www.vupen.com/english/advisories/2010/2323