CVE-2009-0771
published 2009-03-05CVE-2009-0771: The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service…
PriorityP335critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.61%
90.6th percentile
The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures.
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.6 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-03-05·CVSS 6.8
CVE-2009-0773 [MEDIUM] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Glenn Randers-Pehrson discovered that the embedded libpng in Firefox
did not properly initialize pointers. If a user were tricked into
viewing a malicious website with a crafted PNG file, a remote attacker
could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-0040)
Martijn Wargers, Jesse Ruderman, Josh Soref, Gary Kwong, and Timothee
Groleau discovered flaws in the browser engine. If a user were tricked
into viewing a malicious website, a remote attacker could cause a
denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-0771,
CVE-2009-0772, CVE-2009-0773, CV
Red Hat
Firefox 3 Layout Engine Crashes
vendor_redhat·2009-03-04·CVSS 10.0
CVE-2009-0771 [CRITICAL] Firefox 3 Layout Engine Crashes
Firefox 3 Layout Engine Crashes
The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures.
GHSA
GHSA-wqhc-6m34-q79w: The layout engine in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-0771 [HIGH] GHSA-wqhc-6m34-q79w: The layout engine in Mozilla Firefox before 3
The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.htmlhttp://secunia.com/advisories/34140http://secunia.com/advisories/34145http://secunia.com/advisories/34272http://secunia.com/advisories/34383http://secunia.com/advisories/34462http://secunia.com/advisories/34464http://secunia.com/advisories/34527http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.405420http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.433952http://support.avaya.com/elmodocs2/security/ASA-2009-069.htmhttp://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.productID=154235&temp.releaseID=361845&temp.bucketID=126655&PAGE=Documenthttp://www.debian.org/security/2009/dsa-1751http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:075http://www.mandriva.com/security/advisories?name=MDVSA-2009:083http://www.mozilla.org/security/announce/2009/mfsa2009-07.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0315.htmlhttp://www.securityfocus.com/bid/33990http://www.securitytracker.com/id?1021795http://www.vupen.com/english/advisories/2009/0632https://bugzilla.mozilla.org/buglist.cgi?bug_id=424276%2C435209%2C436965%2C460706%2C466057%2C468578%2C471594%2C472502https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11314https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5250https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6163https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6196https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6755https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.htmlhttp://secunia.com/advisories/34140http://secunia.com/advisories/34145http://secunia.com/advisories/34272http://secunia.com/advisories/34383http://secunia.com/advisories/34462http://secunia.com/advisories/34464http://secunia.com/advisories/34527http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.405420http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.433952http://support.avaya.com/elmodocs2/security/ASA-2009-069.htmhttp://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.productID=154235&temp.releaseID=361845&temp.bucketID=126655&PAGE=Documenthttp://www.debian.org/security/2009/dsa-1751http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:075http://www.mandriva.com/security/advisories?name=MDVSA-2009:083http://www.mozilla.org/security/announce/2009/mfsa2009-07.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0315.htmlhttp://www.securityfocus.com/bid/33990http://www.securitytracker.com/id?1021795http://www.vupen.com/english/advisories/2009/0632https://bugzilla.mozilla.org/buglist.cgi?bug_id=424276%2C435209%2C436965%2C460706%2C466057%2C468578%2C471594%2C472502https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11314https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5250https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6163https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6196https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6755https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html
2009-03-05
Published