VYPR
Unrated severityNVD Advisory· Published Oct 21, 2010· Updated Apr 29, 2026

CVE-2010-3177

CVE-2010-3177

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Gopher parser in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, and SeaMonkey before 2.0.9, allow remote attackers to inject arbitrary web script or HTML via a crafted name of a (1) file or (2) directory on a Gopher server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site scripting vulnerability in Firefox and SeaMonkey Gopher parser allows arbitrary script execution via malformed file/directory names.

Vulnerability

The Gopher parser in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, and SeaMonkey before 2.0.9, contains multiple cross-site scripting (XSS) vulnerabilities. When a user accesses a Gopher server, a crafted name of a file or directory on that server can inject arbitrary web script or HTML. The parser fails to properly escape the name when converting it to HTML [1][2][3].

Exploitation

An attacker must control a Gopher server or be able to serve a maliciously named file/directory from a Gopher server. The victim simply needs to browse to the Gopher server using Firefox or SeaMonkey. No additional authentication or user interaction beyond standard browsing is required; the malformed name is automatically processed when the directory listing is rendered [1][3].

Impact

Successful exploitation allows arbitrary JavaScript execution in the context of the Gopher domain. This can lead to theft of cookies or other sensitive data, UI spoofing, or actions performed on behalf of the victim within that Gopher session [1][2][3]. The attack is constrained to the Gopher protocol's origin.

Mitigation

Mozilla released Firefox 3.5.14 and 3.6.11 on October 19, 2010, and SeaMonkey 2.0.9 on the same date. Users should update to these or later versions. Red Hat provided updates via RHSA-2010-0781 and RHSA-2010-0782; Ubuntu via USN-997-1. No workarounds are documented for unpatched versions [1][2][3][4].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

151
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 95 more
    • cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <=3.5.13
    • cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0:preview_release:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.15:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.16:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.17:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.18:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.19:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.20:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.15:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.16:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.17:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.6.9:*:*:*:*:*:*:*
    • (no CPE)range: <=3.5.13, >=3.6 <=3.6.10
  • cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*+ 52 more
    • cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*range: <=2.0.8
    • cpe:2.3:a:mozilla:seamonkey:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0:alpha:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.15:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.16:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.17:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.18:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.19:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1:alpha:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1:beta:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.5.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.5.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.5.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:beta_1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:beta_2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:rc2:*:*:*:*:*:*
  • osv-coords2 versions
    < 128.5.1-1.1+ 1 more
    • (no CPE)range: < 128.5.1-1.1
    • (no CPE)range: < 50.1.0-1.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

16

News mentions

0

No linked articles in our index yet.