CVE-2009-2408
- EPSS 1.69%
- Published 30.07.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certif...
- EPSS 5.33%
- Published 22.07.2009 18:30:00
- Last modified 09.04.2025 00:30:58
The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) the frame chain and synch...
- EPSS 4.17%
- Published 22.07.2009 18:30:00
- Last modified 09.04.2025 00:30:58
Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a deni...
- EPSS 19.04%
- Published 22.07.2009 18:30:00
- Last modified 09.04.2025 00:30:58
The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arb...
- EPSS 5.81%
- Published 22.07.2009 18:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving double frame construction, related to (1) nsHTMLContentSink.cp...
- EPSS 4.98%
- Published 22.07.2009 18:30:00
- Last modified 25.06.2025 16:56:21
The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2...
- EPSS 5.19%
- Published 22.07.2009 18:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a Flash object, a slow script dialog, and the unloading of the Flash ...
- EPSS 23.74%
- Published 22.07.2009 18:30:00
- Last modified 09.04.2025 00:30:58
Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ...
- EPSS 4.12%
- Published 22.07.2009 18:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to cause a denial of service (memory corruption and application crash) or ...
- EPSS 2.11%
- Published 22.07.2009 18:30:00
- Last modified 09.04.2025 00:30:58
The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.