CVE-2009-1304Out-of-bounds Write in Mozilla Seamonkey

CWE-3996 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
6.7%
top 8.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateMay 2

Description

The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving (1) js_FindPropertyHelper, related to the definitions of Math and Date; and (2) js_CheckRedeclaration.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/seamonkey1.1.13+24
NVDmozilla/thunderbird2.0.0.19+38
NVDmozilla/firefox9 versions+8

🔴Vulnerability Details

2
GHSA
GHSA-62pj-m994-qpwg: The JavaScript engine in Mozilla Firefox 32022-05-02
CVEList
CVE-2009-1304: The JavaScript engine in Mozilla Firefox 32009-04-22

📋Vendor Advisories

2
Ubuntu
Firefox and Xulrunner vulnerabilities2009-04-23
Red Hat
Firefox 3 JavaScript engine crashes2009-04-21

💬Community

1
Bugzilla
CVE-2009-1304 Firefox 3 JavaScript engine crashes2009-04-17
CVE-2009-1304 — Out-of-bounds Write in Mozilla | cvebase