CVE-2009-1302Out-of-bounds Write in Mozilla Seamonkey

CWE-39910 documents6 sources
Severity
9.3CRITICALNVD
NVD5.0CNA5.0
EPSS
4.4%
top 10.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateMay 2

Description

The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAnc

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/seamonkey1.1.13+24
NVDmozilla/thunderbird2.0.0.19+38
NVDmozilla/firefox10 versions+9

🔴Vulnerability Details

4
GHSA
GHSA-r98g-pww2-x9wj: The browser engine in Mozilla Firefox 32022-05-02
GHSA
GHSA-ph69-fr9j-4gj2: The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes2022-05-02
CVEList
CVE-2009-1313: The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes2009-04-30
CVEList
CVE-2009-1302: The browser engine in Mozilla Firefox 32009-04-22

📋Vendor Advisories

3
Red Hat
nsTextFrame:: ClearTextRun()2009-04-27
Ubuntu
Firefox and Xulrunner vulnerabilities2009-04-23
Red Hat
Firefox 3 Layout engine crashes2009-04-21

💬Community

1
Bugzilla
CVE-2009-1302 Firefox 3 Layout engine crashes2009-04-17
CVE-2009-1302 — Out-of-bounds Write in Mozilla | cvebase