CVE-2009-1305Out-of-bounds Write in Mozilla Seamonkey

CWE-3998 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
4.7%
top 10.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateMay 2

Description

The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving JSOP_DEFVAR and properties that lack the JSPROP_PERMANENT attribute.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/seamonkey1.1.13+24
NVDmozilla/thunderbird2.0.0.19+38
NVDmozilla/firefox9 versions+8

🔴Vulnerability Details

2
GHSA
GHSA-275w-m9g6-w2cc: The JavaScript engine in Mozilla Firefox before 32022-05-02
CVEList
CVE-2009-1305: The JavaScript engine in Mozilla Firefox before 32009-04-22

💥Exploits & PoCs

1
Exploit-DB
Joomla! Component JInventory 1.23.02 - Local File Inclusion2010-04-05

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2009-06-25
Ubuntu
Firefox and Xulrunner vulnerabilities2009-04-23
Red Hat
Firefox 2 and 3 JavaScript engine crash2009-04-21

💬Community

1
Bugzilla
CVE-2009-1305 Firefox 2 and 3 JavaScript engine crash2009-04-17
CVE-2009-1305 — Out-of-bounds Write in Mozilla | cvebase