CVE-2010-3171 describes a vulnerability in the Math.random function within Mozilla Firefox versions 3.5.10-3.5.11, 3.6.4-3.6.8, and 4.0 Beta1. The flaw stems from the random number generator being seeded only once per document object, making it susceptible to seed value calculation. This medium-severity vulnerability (CVSS 5.8) allows remote attackers to track users or facilitate in-session phishing attacks due to the network-based attack vector and medium attack complexity, potentially leading to partial confidentiality and integrity compromise. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry (EDB-34621) exists, and the CVE has minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.5.10CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.5.10:*:*:*:*:*:*:* | ||
3.5.11CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.5.11:*:*:*:*:*:*:* | ||
3.6.4CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.6.4:*:*:*:*:*:*:* | ||
3.6.6CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.6.6:*:*:*:*:*:*:* | ||
3.6.7CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.6.7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.