CVE-2009-1303Out-of-bounds Write in Mozilla Firefox

CWE-167 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
2.8%
top 13.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateMay 2

Description

The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/firefox3.0.8+78
NVDmozilla/seamonkey1.1.15+29
NVDmozilla/thunderbird2.0.0.21+68

🔴Vulnerability Details

2
GHSA
GHSA-g69g-mf2j-vrwq: The browser engine in Mozilla Firefox before 32022-05-02
CVEList
CVE-2009-1303: The browser engine in Mozilla Firefox before 32009-04-22

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2009-06-25
Ubuntu
Firefox and Xulrunner vulnerabilities2009-04-23
Red Hat
Firefox 2 and 3 Layout engine crash2009-04-21

💬Community

1
Bugzilla
CVE-2009-1303 Firefox 2 and 3 Layout engine crash2009-04-17
CVE-2009-1303 — Out-of-bounds Write in Mozilla Firefox | cvebase