CVE-2009-1571Code Injection in Mozilla Firefox

CWE-94Code Injection21 documents6 sources
Severity
10.0CRITICALNVD
NVD5.0
EPSS
7.1%
top 8.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22
Latest updateMay 14

Description

Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDmozilla/firefox26 versions+25
NVDmozilla/seamonkey31 versions+30

🔴Vulnerability Details

8
GHSA
GHSA-mqrf-j5vq-j64f: Mozilla Firefox 32022-05-14
GHSA
GHSA-5f63-6j8r-v53q: Mozilla Firefox 32022-05-14
GHSA
GHSA-9gqx-f57m-x5j2: Mozilla Firefox 32022-05-14
GHSA
GHSA-prv5-qjj9-xp4f: Use-after-free vulnerability in the HTML parser in Mozilla Firefox 32022-05-02
CVEList
CVE-2010-1988: Mozilla Firefox 32010-05-20

📋Vendor Advisories

3
Red Hat
Mozilla incorrectly frees used memory (MFSA 2010-03)2010-02-17
Ubuntu
Firefox 3.0 and Xulrunner 1.9 vulnerabilities2010-02-17
Ubuntu
Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities2010-02-17

💬Community

3
Bugzilla
CVE-2009-1571 Mozilla incorrectly frees used memory (MFSA 2010-03)2010-02-17
Bugzilla
CVE-2009-3884 OpenJDK zoneinfo file existence information leak (6824265)2009-10-22
Bugzilla
CVE-2009-3879 OpenJDK GraphicsConfiguration information leak(6822057)2009-10-22
CVE-2009-1571 — Code Injection in Mozilla Firefox | cvebase