CVE-2009-0775Double Free in Mozilla Firefox

CWE-3996 documents6 sources
Severity
10.0CRITICALNVD
EPSS
6.6%
top 8.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 5
Latest updateMay 2

Description

Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

NVDmozilla/firefox3.0.6+49
NVDmozilla/seamonkey1.1.14+23
NVDmozilla/thunderbird2.0.0.20+11

🔴Vulnerability Details

2
GHSA
GHSA-rgh3-gqjf-4mqv: Double free vulnerability in Mozilla Firefox before 32022-05-02
CVEList
CVE-2009-0775: Double free vulnerability in Mozilla Firefox before 32009-03-05

📋Vendor Advisories

2
Ubuntu
Firefox and Xulrunner vulnerabilities2009-03-05
Red Hat
Firefox XUL Linked Clones Double Free Vulnerability2009-03-04

💬Community

1
Bugzilla
CVE-2009-0775 Firefox XUL Linked Clones Double Free Vulnerability2009-03-03
CVE-2009-0775 — Double Free in Mozilla Firefox | cvebase