CVE-2010-3166

Heap-based buffer overflow in the nsTextFrameUtils::TransformText function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a bidirectional text run.

Date published : 2010-09-09

http://www.securityfocus.com/bid/43102

http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox