Field Assessment
AI analysis pending.
CVE
CVE-2010-3768
Severity
HIGH
CVSS
9.3
EPSS
4.81%
Firefox
Original Filing — NVD Description
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly validate downloadable fonts before use within an operating system's font implementation, which allows remote attackers to execute arbitrary code via vectors related to @font-face Cascading Style Sheets (CSS) rules.