10

CVE-2009-2466

Exploit

The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.

Data is provided by the National Vulnerability Database (NVD)
MozillaFirefox Version < 3.0.12
MozillaThunderbird Version <= 3.0.11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.98% 0.893
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://secunia.com/advisories/35914
Vendor Advisory
Not Applicable
http://secunia.com/advisories/35943
Vendor Advisory
Not Applicable
http://secunia.com/advisories/35944
Patch
Vendor Advisory
Not Applicable
http://secunia.com/advisories/35947
Vendor Advisory
Not Applicable
https://bugzilla.mozilla.org/show_bug.cgi?id=454704
Vendor Advisory
Exploit
Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=493281
Patch
Vendor Advisory
Issue Tracking