CVE-2009-0775
published 2009-03-05CVE-2009-0775: Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute…
PriorityP347critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.71%
90.8th percentile
Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection.
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.6 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-03-05·CVSS 6.8
CVE-2009-0773 [MEDIUM] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Glenn Randers-Pehrson discovered that the embedded libpng in Firefox
did not properly initialize pointers. If a user were tricked into
viewing a malicious website with a crafted PNG file, a remote attacker
could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-0040)
Martijn Wargers, Jesse Ruderman, Josh Soref, Gary Kwong, and Timothee
Groleau discovered flaws in the browser engine. If a user were tricked
into viewing a malicious website, a remote attacker could cause a
denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-0771,
CVE-2009-0772, CVE-2009-0773, CV
Red Hat
Firefox XUL Linked Clones Double Free Vulnerability
vendor_redhat·2009-03-04·CVSS 10.0
CVE-2009-0775 [CRITICAL] Firefox XUL Linked Clones Double Free Vulnerability
Firefox XUL Linked Clones Double Free Vulnerability
Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection.
GHSA
GHSA-rgh3-gqjf-4mqv: Double free vulnerability in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-0775 [HIGH] GHSA-rgh3-gqjf-4mqv: Double free vulnerability in Mozilla Firefox before 3
Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.htmlhttp://secunia.com/advisories/34137http://secunia.com/advisories/34140http://secunia.com/advisories/34145http://secunia.com/advisories/34272http://secunia.com/advisories/34324http://secunia.com/advisories/34383http://secunia.com/advisories/34417http://support.avaya.com/elmodocs2/security/ASA-2009-069.htmhttp://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.productID=154235&temp.releaseID=361845&temp.bucketID=126655&PAGE=Documenthttp://www.debian.org/security/2009/dsa-1751http://www.mandriva.com/security/advisories?name=MDVSA-2009:075http://www.mozilla.org/security/announce/2009/mfsa2009-08.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0258.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0315.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0325.htmlhttp://www.securityfocus.com/bid/33990http://www.securitytracker.com/id?1021796http://www.vupen.com/english/advisories/2009/0632https://bugzilla.mozilla.org/show_bug.cgi?id=474456https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5806https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5816https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6207https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7584https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9681https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.htmlhttp://secunia.com/advisories/34137http://secunia.com/advisories/34140http://secunia.com/advisories/34145http://secunia.com/advisories/34272http://secunia.com/advisories/34324http://secunia.com/advisories/34383http://secunia.com/advisories/34417http://support.avaya.com/elmodocs2/security/ASA-2009-069.htmhttp://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.productID=154235&temp.releaseID=361845&temp.bucketID=126655&PAGE=Documenthttp://www.debian.org/security/2009/dsa-1751http://www.mandriva.com/security/advisories?name=MDVSA-2009:075http://www.mozilla.org/security/announce/2009/mfsa2009-08.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0258.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0315.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0325.htmlhttp://www.securityfocus.com/bid/33990http://www.securitytracker.com/id?1021796http://www.vupen.com/english/advisories/2009/0632https://bugzilla.mozilla.org/show_bug.cgi?id=474456https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5806https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5816https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6207https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7584https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9681https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.html
2009-03-05
Published