Oval Definition:oval:org.mitre.oval:def:11863
Revision Date:2014-10-06Version:28
Title:Mozilla Firefox and Thunderbird Characters mapped to U+FFFD in 8 bit encodings cause subsequent character to vanish
Description:intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 inserts a U+FFFD sequence into text in certain circumstances involving undefined positions, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted 8-bit text.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2010-1210
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Mozilla Firefox
Mozilla Thunderbird
Definition Synopsis
  • Check for vulnerable Firefox mainline
  • Mozilla Firefox Mainline release is installed
  • AND Check for vulnerable version
  • Mozilla Firefox Mainline version is 3.6.x before 3.6.7
  • OR Check for vulnerable Thunderbird Mainline
  • Mozilla Thunderbird Mainline release is installed
  • AND Mozilla Thunderbird 3.1.x before 3.1.1
  • BACK