{
  "threat_severity" : "Critical",
  "public_date" : "2010-07-20T00:00:00Z",
  "bugzilla" : {
    "description" : "Mozilla nsTreeSelection dangling pointer remote code execution vulnerability",
    "id" : "615466",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=615466"
  },
  "cvss" : {
    "cvss_base_score" : "6.8",
    "cvss_scoring_vector" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
    "status" : "verified"
  },
  "details" : [ "Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 3",
    "release_date" : "2010-07-21T00:00:00Z",
    "advisory" : "RHSA-2010:0546",
    "cpe" : "cpe:/o:redhat:enterprise_linux:3",
    "package" : "seamonkey-0:1.0.9-0.57.el3"
  }, {
    "product_name" : "Red Hat Enterprise Linux 4",
    "release_date" : "2010-07-21T00:00:00Z",
    "advisory" : "RHSA-2010:0544",
    "cpe" : "cpe:/o:redhat:enterprise_linux:4",
    "package" : "thunderbird-0:1.5.0.12-28.el4",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Enterprise Linux 4",
    "release_date" : "2010-07-21T00:00:00Z",
    "advisory" : "RHSA-2010:0546",
    "cpe" : "cpe:/o:redhat:enterprise_linux:4",
    "package" : "seamonkey-0:1.0.9-60.el4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 4",
    "release_date" : "2010-07-21T00:00:00Z",
    "advisory" : "RHSA-2010:0547",
    "cpe" : "cpe:/o:redhat:enterprise_linux:4",
    "package" : "firefox-0:3.6.7-2.el4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2010-07-21T00:00:00Z",
    "advisory" : "RHSA-2010:0545",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "thunderbird-0:2.0.0.24-6.el5",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2010-07-21T00:00:00Z",
    "advisory" : "RHSA-2010:0547",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "firefox-0:3.6.7-2.el5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2010-07-21T00:00:00Z",
    "advisory" : "RHSA-2010:0547",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "xulrunner-0:1.9.2.7-2.el5"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "firefox",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2010-2753\nhttps://nvd.nist.gov/vuln/detail/CVE-2010-2753" ],
  "name" : "CVE-2010-2753",
  "csaw" : false
}