CVE-2009-1302
published 2009-04-22CVE-2009-1302: The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of…
PriorityP419medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.90%
85.5th percentile
The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors.
Affected
74 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 1.1.13 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_ubuntu5.8MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nsTextFrame:: ClearTextRun()
vendor_redhat·2009-04-27·CVSS 5.0
CVE-2009-1313 [MEDIUM] nsTextFrame:: ClearTextRun()
nsTextFrame:: ClearTextRun()
The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2009-1302.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-04-23·CVSS 5.8
CVE-2009-1302 [MEDIUM] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Several flaws were discovered in the browser engine. If a user were tricked
into viewing a malicious website, a remote attacker could cause a denial of
service or possibly execute arbitrary code with the privileges of the user
invoking the program. (CVE-2009-1302, CVE-2009-1303, CVE-2009-1304,
CVE-2009-1305)
It was discovered that Firefox displayed certain Unicode characters which
could be visually confused with punctuation in valid web addresses in the
location bar. An attacker could exploit this to spoof the location bar,
such as in a phishing attack. (CVE-2009-0652)
Several flaws were discovered in the way Firefox processed malformed URI
schemes. If a user were tricked into viewing a maliciou
Red Hat
Firefox 3 Layout engine crashes
vendor_redhat·2009-04-21·CVSS 5.0
CVE-2009-1302 [MEDIUM] Firefox 3 Layout engine crashes
Firefox 3 Layout engine crashes
The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors.
GHSA
GHSA-r98g-pww2-x9wj: The browser engine in Mozilla Firefox 3
ghsa_unreviewed·2022-05-02
CVE-2009-1302 [MEDIUM] GHSA-r98g-pww2-x9wj: The browser engine in Mozilla Firefox 3
The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors.
GHSA
GHSA-ph69-fr9j-4gj2: The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2009-1313 [MEDIUM] GHSA-ph69-fr9j-4gj2: The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes
The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2009-1302.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://secunia.com/advisories/34758http://secunia.com/advisories/34780http://secunia.com/advisories/34843http://secunia.com/advisories/34894http://secunia.com/advisories/35042http://secunia.com/advisories/35065http://secunia.com/advisories/35602http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1http://www.debian.org/security/2009/dsa-1797http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:111http://www.mandriva.com/security/advisories?name=MDVSA-2009:141http://www.mozilla.org/security/announce/2009/mfsa2009-14.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0436.htmlhttp://www.securityfocus.com/bid/34656http://www.securitytracker.com/id?1022090http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.454275http://www.vupen.com/english/advisories/2009/1125https://bugzilla.mozilla.org/show_bug.cgi?id=428113https://bugzilla.mozilla.org/show_bug.cgi?id=431260https://bugzilla.mozilla.org/show_bug.cgi?id=432114https://bugzilla.mozilla.org/show_bug.cgi?id=454276https://bugzilla.mozilla.org/show_bug.cgi?id=461053https://bugzilla.mozilla.org/show_bug.cgi?id=462517https://bugzilla.mozilla.org/show_bug.cgi?id=467881https://bugzilla.mozilla.org/show_bug.cgi?id=477775https://bugzilla.mozilla.org/show_bug.cgi?id=483444https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10106https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5527https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6070https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6170https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7030https://usn.ubuntu.com/764-1/https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://secunia.com/advisories/34758http://secunia.com/advisories/34780http://secunia.com/advisories/34843http://secunia.com/advisories/34894http://secunia.com/advisories/35042http://secunia.com/advisories/35065http://secunia.com/advisories/35602http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1http://www.debian.org/security/2009/dsa-1797http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:111http://www.mandriva.com/security/advisories?name=MDVSA-2009:141http://www.mozilla.org/security/announce/2009/mfsa2009-14.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0436.htmlhttp://www.securityfocus.com/bid/34656http://www.securitytracker.com/id?1022090http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.454275http://www.vupen.com/english/advisories/2009/1125https://bugzilla.mozilla.org/show_bug.cgi?id=428113https://bugzilla.mozilla.org/show_bug.cgi?id=431260https://bugzilla.mozilla.org/show_bug.cgi?id=432114https://bugzilla.mozilla.org/show_bug.cgi?id=454276https://bugzilla.mozilla.org/show_bug.cgi?id=461053https://bugzilla.mozilla.org/show_bug.cgi?id=462517https://bugzilla.mozilla.org/show_bug.cgi?id=467881https://bugzilla.mozilla.org/show_bug.cgi?id=477775https://bugzilla.mozilla.org/show_bug.cgi?id=483444https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10106https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5527https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6070https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6170https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7030https://usn.ubuntu.com/764-1/https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html
2009-04-22
Published