CVE-2009-0774
published 2009-03-05CVE-2009-0774: The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of…
PriorityP334critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.05%
89.6th percentile
The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773.
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.6 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2009-03-19·CVSS 10.0
CVE-2009-0352 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Several flaws were discovered in the browser engine. If Javascript were
enabled, an attacker could exploit these flaws to crash Thunderbird and
possibly execute arbitrary code with user privileges. (CVE-2009-0352)
Jesse Ruderman and Gary Kwong discovered flaws in the browser engine. If a
user had Javascript enabled, these problems could allow a remote attacker to
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-0772, CVE-2009-0774)
Georgi Guninski discovered a flaw when Thunderbird performed a cross-domain
redirect. If a user had Javascript enabled, an attacker could bypass the
same-origin policy in Thunderbird by utilizing nsIRDFService an
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2009-03-06·CVSS 9.3
CVE-2009-0776 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Jesse Ruderman and Gary Kwong discovered flaws in the browser engine.
If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary
code with the privileges of the user invoking the program.
(CVE-2009-0772, CVE-2009-0774)
Georgi Guninski discovered a flaw when Firefox performed a
cross-domain redirect. An attacker could bypass the same-origin policy
in Firefox by utilizing nsIRDFService and steal private data from
users authenticated to the redirected website. (CVE-2009-0776)
Instructions: After a standard system upgrade you need to restart Firefox to effect the
necessary changes.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2009-03-06·CVSS 9.3
CVE-2009-0772 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Jesse Ruderman and Gary Kwong discovered flaws in the browser engine.
If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary
code with the privileges of the user invoking the program.
(CVE-2009-0772, CVE-2009-0774)
Georgi Guninski discovered a flaw when Firefox performed a
cross-domain redirect. An attacker could bypass the same-origin policy
in Firefox by utilizing nsIRDFService and steal private data from
users authenticated to the redirected website. (CVE-2009-0776)
Instructions: After a standard system upgrade you need to restart Firefox to effect the
necessary changes.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-03-05·CVSS 6.8
CVE-2009-0773 [MEDIUM] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Glenn Randers-Pehrson discovered that the embedded libpng in Firefox
did not properly initialize pointers. If a user were tricked into
viewing a malicious website with a crafted PNG file, a remote attacker
could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-0040)
Martijn Wargers, Jesse Ruderman, Josh Soref, Gary Kwong, and Timothee
Groleau discovered flaws in the browser engine. If a user were tricked
into viewing a malicious website, a remote attacker could cause a
denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-0771,
CVE-2009-0772, CVE-2009-0773, CV
Red Hat
Firefox 2 and 3 crashes in the JavaScript engine
vendor_redhat·2009-03-04·CVSS 10.0
CVE-2009-0774 [CRITICAL] Firefox 2 and 3 crashes in the JavaScript engine
Firefox 2 and 3 crashes in the JavaScript engine
The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773.
GHSA
GHSA-7366-2x8r-hhqr: The layout engine in Mozilla Firefox 2 and 3 before 3
ghsa_unreviewed·2022-05-02·CVSS 10.0
CVE-2009-0774 [CRITICAL] GHSA-7366-2x8r-hhqr: The layout engine in Mozilla Firefox 2 and 3 before 3
The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-5005 qpid: crash on receipt of invalid AMQP data
bugzilla·2010-10-12·CVSS 5.0
CVE-2009-5005 [MEDIUM] CVE-2009-5005 qpid: crash on receipt of invalid AMQP data
CVE-2009-5005 qpid: crash on receipt of invalid AMQP data
It was reported [1] that Apache QPID would crash when receiving data from a client that is not valid AMQP data, resulting in a shut down of the cluster rather than the client being disconnected. This was corrected upstream by r785788 [2].
[1] https://bugzilla.redhat.com/show_bug.cgi?id=506580
[2] http://svn.apache.org/viewvc?revision=785788&view=revision
Discussion:
This issue has been addressed in following products:
MRG for RHEL-5
Via RHSA-2010:0773 https://rhn.redhat.com/errata/RHSA-2010-0773.html
---
This issue has been addressed in following products:
Grid for MRG on RHEL-4
Messaging for MRG on RHEL-4
Grid Execute Node for MRG on RHEL-4
Messaging Base for MRG on RHEL-4
Via RHSA-2010:0774 https://rhn.redhat.com/errata/
Bugzilla
CVE-2009-0774 Firefox 2 and 3 crashes in the JavaScript engine
bugzilla·2009-03-03·CVSS 9.3
CVE-2009-0774 [CRITICAL] CVE-2009-0774 Firefox 2 and 3 crashes in the JavaScript engine
CVE-2009-0774 Firefox 2 and 3 crashes in the JavaScript engine
Mozilla developers identified and fixed several stability bugs in the
browser engine used in Firefox and other Mozilla-based products. Some of
these crashes showed evidence of memory corruption under certain
circumstances and we presume that with enough effort at least some of these
could be exploited to run arbitrary code.
Gary Kwong reported a crashe in the JavaScript engine which affected
Firefox 2 and 3.
Discussion:
Public now via:
http://www.mozilla.org/security/announce/2009/mfsa2009-07.html
---
firefox-3.0.7-1.fc9, xulrunner-1.9.0.7-1.fc9, epiphany-2.22.2-8.fc9, epiphany-extensions-2.22.1-8.fc9, blam-1.8.5-6.fc9.1, chmsee-1.0.1-9.fc9, devhelp-0.19.1-9.fc9, galeon-2.0.7-7.fc9, gnome-python2-extras-2.19.1-24.fc9, gno
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.htmlhttp://secunia.com/advisories/34137http://secunia.com/advisories/34140http://secunia.com/advisories/34145http://secunia.com/advisories/34272http://secunia.com/advisories/34324http://secunia.com/advisories/34383http://secunia.com/advisories/34387http://secunia.com/advisories/34417http://secunia.com/advisories/34462http://secunia.com/advisories/34464http://secunia.com/advisories/34527http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.405420http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.433952http://support.avaya.com/elmodocs2/security/ASA-2009-069.htmhttp://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.productID=154235&temp.releaseID=361845&temp.bucketID=126655&PAGE=Documenthttp://www.debian.org/security/2009/dsa-1751http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:075http://www.mandriva.com/security/advisories?name=MDVSA-2009:083http://www.mozilla.org/security/announce/2009/mfsa2009-07.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0258.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0315.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0325.htmlhttp://www.securityfocus.com/bid/33990http://www.securitytracker.com/id?1021795http://www.vupen.com/english/advisories/2009/0632https://bugzilla.mozilla.org/show_bug.cgi?id=473709https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11138https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5947https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6057https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6121https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6945https://usn.ubuntu.com/741-1/https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.htmlhttp://secunia.com/advisories/34137http://secunia.com/advisories/34140http://secunia.com/advisories/34145http://secunia.com/advisories/34272http://secunia.com/advisories/34324http://secunia.com/advisories/34383http://secunia.com/advisories/34387http://secunia.com/advisories/34417http://secunia.com/advisories/34462http://secunia.com/advisories/34464http://secunia.com/advisories/34527http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.405420http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.433952http://support.avaya.com/elmodocs2/security/ASA-2009-069.htmhttp://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.productID=154235&temp.releaseID=361845&temp.bucketID=126655&PAGE=Documenthttp://www.debian.org/security/2009/dsa-1751http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:075http://www.mandriva.com/security/advisories?name=MDVSA-2009:083http://www.mozilla.org/security/announce/2009/mfsa2009-07.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0258.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0315.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0325.htmlhttp://www.securityfocus.com/bid/33990http://www.securitytracker.com/id?1021795http://www.vupen.com/english/advisories/2009/0632https://bugzilla.mozilla.org/show_bug.cgi?id=473709https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11138https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5947https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6057https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6121https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6945https://usn.ubuntu.com/741-1/https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html
2009-03-05
Published