CVE-2009-0773
published 2009-03-05CVE-2009-0773: The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service…
PriorityP338critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.79%
92.3th percentile
The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang.
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.6 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-03-05·CVSS 6.8
CVE-2009-0773 [MEDIUM] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Glenn Randers-Pehrson discovered that the embedded libpng in Firefox
did not properly initialize pointers. If a user were tricked into
viewing a malicious website with a crafted PNG file, a remote attacker
could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-0040)
Martijn Wargers, Jesse Ruderman, Josh Soref, Gary Kwong, and Timothee
Groleau discovered flaws in the browser engine. If a user were tricked
into viewing a malicious website, a remote attacker could cause a
denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-0771,
CVE-2009-0772, CVE-2009-0773, CV
Red Hat
Firefox 3 crashes in the JavaScript engine
vendor_redhat·2009-03-04·CVSS 10.0
CVE-2009-0773 [CRITICAL] Firefox 3 crashes in the JavaScript engine
Firefox 3 crashes in the JavaScript engine
The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang.
Red Hat
Firefox 2 and 3 crashes in the JavaScript engine
vendor_redhat·2009-03-04·CVSS 10.0
CVE-2009-0774 [CRITICAL] Firefox 2 and 3 crashes in the JavaScript engine
Firefox 2 and 3 crashes in the JavaScript engine
The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773.
GHSA
GHSA-7366-2x8r-hhqr: The layout engine in Mozilla Firefox 2 and 3 before 3
ghsa_unreviewed·2022-05-02·CVSS 10.0
CVE-2009-0774 [CRITICAL] GHSA-7366-2x8r-hhqr: The layout engine in Mozilla Firefox 2 and 3 before 3
The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773.
GHSA
GHSA-fqq3-4hpj-9cxh: The JavaScript engine in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-0773 [HIGH] GHSA-fqq3-4hpj-9cxh: The JavaScript engine in Mozilla Firefox before 3
The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-5006 qpid: crash when redeclaring the exchange with specified alternate_exchange
bugzilla·2010-10-12·CVSS 4.0
CVE-2009-5006 [MEDIUM] CVE-2009-5006 qpid: crash when redeclaring the exchange with specified alternate_exchange
CVE-2009-5006 qpid: crash when redeclaring the exchange with specified alternate_exchange
It was reported [1], [2] that Apache QPID would crash due to a NULL pointer dereference when a remote, authenticated user attempted to redeclare an existing exchange and add a new alternate exchange. This would result in a denial of service condition of the server. This was corrected upstream by r811188 [3].
[1] https://issues.apache.org/jira/browse/QPID-2080
[2] https://bugzilla.redhat.com/show_bug.cgi?id=517751
[3] http://svn.apache.org/viewvc?revision=811188&view=revision
Discussion:
This issue has been addressed in following products:
MRG for RHEL-5
Via RHSA-2010:0773 https://rhn.redhat.com/errata/RHSA-2010-0773.html
---
This issue has been addressed in following products:
Grid for MRG on
Bugzilla
CVE-2009-5005 qpid: crash on receipt of invalid AMQP data
bugzilla·2010-10-12·CVSS 5.0
CVE-2009-5005 [MEDIUM] CVE-2009-5005 qpid: crash on receipt of invalid AMQP data
CVE-2009-5005 qpid: crash on receipt of invalid AMQP data
It was reported [1] that Apache QPID would crash when receiving data from a client that is not valid AMQP data, resulting in a shut down of the cluster rather than the client being disconnected. This was corrected upstream by r785788 [2].
[1] https://bugzilla.redhat.com/show_bug.cgi?id=506580
[2] http://svn.apache.org/viewvc?revision=785788&view=revision
Discussion:
This issue has been addressed in following products:
MRG for RHEL-5
Via RHSA-2010:0773 https://rhn.redhat.com/errata/RHSA-2010-0773.html
---
This issue has been addressed in following products:
Grid for MRG on RHEL-4
Messaging for MRG on RHEL-4
Grid Execute Node for MRG on RHEL-4
Messaging Base for MRG on RHEL-4
Via RHSA-2010:0774 https://rhn.redhat.com/errata/
Bugzilla
CVE-2009-0773 Firefox 3 crashes in the JavaScript engine
bugzilla·2009-03-03·CVSS 10.0
CVE-2009-0773 [CRITICAL] CVE-2009-0773 Firefox 3 crashes in the JavaScript engine
CVE-2009-0773 Firefox 3 crashes in the JavaScript engine
Mozilla developers identified and fixed several stability bugs in the
browser engine used in Firefox and other Mozilla-based products. Some of
these crashes showed evidence of memory corruption under certain
circumstances and we presume that with enough effort at least some of these
could be exploited to run arbitrary code.
Gary Kwong, and Timothee Groleau reported crashes in the JavaScript engine
which affected Firefox 3 only.
Discussion:
Public now via:
http://www.mozilla.org/security/announce/2009/mfsa2009-07.html
---
firefox-3.0.7-1.fc9, xulrunner-1.9.0.7-1.fc9, epiphany-2.22.2-8.fc9, epiphany-extensions-2.22.1-8.fc9, blam-1.8.5-6.fc9.1, chmsee-1.0.1-9.fc9, devhelp-0.19.1-9.fc9, galeon-2.0.7-7.fc9, gnome-python2-extras-2.19
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.htmlhttp://secunia.com/advisories/34140http://secunia.com/advisories/34145http://secunia.com/advisories/34272http://secunia.com/advisories/34383http://secunia.com/advisories/34462http://secunia.com/advisories/34464http://secunia.com/advisories/34527http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.405420http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.433952http://support.avaya.com/elmodocs2/security/ASA-2009-069.htmhttp://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.productID=154235&temp.releaseID=361845&temp.bucketID=126655&PAGE=Documenthttp://www.debian.org/security/2009/dsa-1751http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:075http://www.mandriva.com/security/advisories?name=MDVSA-2009:083http://www.mozilla.org/security/announce/2009/mfsa2009-07.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0315.htmlhttp://www.securityfocus.com/bid/33990http://www.securitytracker.com/id?1021795http://www.vupen.com/english/advisories/2009/0632https://bugzilla.mozilla.org/show_bug.cgi?id=457521https://bugzilla.mozilla.org/show_bug.cgi?id=467499https://bugzilla.mozilla.org/show_bug.cgi?id=472787https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10491https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5856https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5980https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6141https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6708https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.htmlhttp://secunia.com/advisories/34140http://secunia.com/advisories/34145http://secunia.com/advisories/34272http://secunia.com/advisories/34383http://secunia.com/advisories/34462http://secunia.com/advisories/34464http://secunia.com/advisories/34527http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.405420http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.433952http://support.avaya.com/elmodocs2/security/ASA-2009-069.htmhttp://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.productID=154235&temp.releaseID=361845&temp.bucketID=126655&PAGE=Documenthttp://www.debian.org/security/2009/dsa-1751http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:075http://www.mandriva.com/security/advisories?name=MDVSA-2009:083http://www.mozilla.org/security/announce/2009/mfsa2009-07.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0315.htmlhttp://www.securityfocus.com/bid/33990http://www.securitytracker.com/id?1021795http://www.vupen.com/english/advisories/2009/0632https://bugzilla.mozilla.org/show_bug.cgi?id=457521https://bugzilla.mozilla.org/show_bug.cgi?id=467499https://bugzilla.mozilla.org/show_bug.cgi?id=472787https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10491https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5856https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5980https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6141https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6708https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html
2009-03-05
Published