---
cve: "CVE-2010-1199"
severity: "LOW"
cvss: 3.1
epss: "11.4%"
vendor: "n/a"
kev: false
exploited: false
published: "2010-06-24 12:30:01"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-15T03:31:14+02:00"
---

# CVE-2010-1199

> 3.1 LOW · 🧪 PoC

## Beschreibung

Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a node.

## Exploit-Evidenz

- [EDB-14949 — Mozilla Firefox 3.6.3 - XSLT Sort Remote Code Execution](https://www.exploit-db.com/exploits/14949) ✅
- [EDB-34192 — Mozilla Firefox/Thunderbird/SeaMonkey - XSLT Integer Overflow](https://www.exploit-db.com/exploits/34192) ✅

## Referenzen

- <https://exchange.xforce.ibmcloud.com/vulnerabilities/59666>
- <http://secunia.com/advisories/40481>
- <http://ubuntu.com/usn/usn-930-1>
- <https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13287>
- <http://www.exploit-db.com/exploits/14949>
- <http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043405.html>
- <http://www.securitytracker.com/id?1024138>
- <http://www.vupen.com/english/advisories/2010/1640>
- <http://www.securityfocus.com/bid/41050>
- <http://www.redhat.com/support/errata/RHSA-2010-0501.html>
- <http://www.vupen.com/english/advisories/2010/1557>
- <http://www.mandriva.com/security/advisories?name=MDVSA-2010:125>
- <http://www.vupen.com/english/advisories/2010/1773>
- <https://bugzilla.mozilla.org/show_bug.cgi?id=554255>
- <http://www.redhat.com/support/errata/RHSA-2010-0499.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2010-1199) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
