CVE-2009-1571
published 2010-02-22CVE-2009-1571: Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before…
PriorityP343critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.39%
92.9th percentile
Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations.
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla SeaMonkey up to 2.0.2 HTML Parser code injection (Bug 526500 / Nessus ID 68000)
vuldb·2026-05-01·CVSS 10.0
CVE-2009-1571 [CRITICAL] Mozilla SeaMonkey up to 2.0.2 HTML Parser code injection (Bug 526500 / Nessus ID 68000)
A vulnerability described as critical has been identified in Mozilla SeaMonkey. Affected by this issue is some unknown functionality of the component HTML Parser. Executing a manipulation can lead to code injection.
This vulnerability is registered as CVE-2009-1571. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-mqrf-j5vq-j64f: Mozilla Firefox 3
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2010-1986 [CRITICAL] GHSA-mqrf-j5vq-j64f: Mozilla Firefox 3
Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption and application crash) via JavaScript code that creates multiple arrays containing elements with long string values, and then appends long strings to the content of a P element, related to the gfxWindowsFontGroup::MakeTextRun function in xul.dll, a different vulnerability than CVE-2009-1571.
GHSA
GHSA-5f63-6j8r-v53q: Mozilla Firefox 3
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2010-1988 [CRITICAL] GHSA-5f63-6j8r-v53q: Mozilla Firefox 3
Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via JavaScript code that performs certain string concatenation and substring operations, a different vulnerability than CVE-2009-1571.
GHSA
GHSA-9gqx-f57m-x5j2: Mozilla Firefox 3
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2010-1987 [CRITICAL] GHSA-9gqx-f57m-x5j2: Mozilla Firefox 3
Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption, out-of-bounds read, and application crash) via JavaScript code that appends long strings to the content of a P element, and performs certain other string concatenation and substring operations, related to the DoubleWideCharMappedString class in USP10.dll and the gfxWindowsFontGroup::GetUnderlineOffset function in xul.dll, a different vulnerability than CVE-2009-1571.
GHSA
GHSA-prv5-qjj9-xp4f: Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3
ghsa_unreviewed·2022-05-02
CVE-2009-1571 [HIGH] CWE-94 GHSA-prv5-qjj9-xp4f: Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3
Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations.
Red Hat
Mozilla incorrectly frees used memory (MFSA 2010-03)
vendor_redhat·2010-02-17·CVSS 10.0
CVE-2009-1571 [CRITICAL] Mozilla incorrectly frees used memory (MFSA 2010-03)
Mozilla incorrectly frees used memory (MFSA 2010-03)
Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations.
Ubuntu
Firefox 3.0 and Xulrunner 1.9 vulnerabilities
vendor_ubuntu·2010-02-17·CVSS 10.0
CVE-2010-0159 [CRITICAL] Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Title: Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Summary: Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious website, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-0159)
Orlando Barrera II discovered a flaw in the Web Workers implementation of
Firefox. If a user were tricked into posting to a malicious website, an
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0160)
Alin Rad Pop discovered that Firefox's HTML parser would incorrectly free
memory under certain circumstances. If the bro
Ubuntu
Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
vendor_ubuntu·2010-02-17·CVSS 10.0
CVE-2010-0160 [CRITICAL] Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Title: Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Summary: Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious website, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-0159)
Orlando Barrera II discovered a flaw in the Web Workers implementation of
Firefox. If a user were tricked into posting to a malicious website, an
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0160)
Alin Rad Pop discovered that Firefox's HTML parser would incorrectly free
memory under certain circumstances. If the
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-1571 Mozilla incorrectly frees used memory (MFSA 2010-03)
bugzilla·2010-02-17·CVSS 10.0
CVE-2009-1571 [CRITICAL] CVE-2009-1571 Mozilla incorrectly frees used memory (MFSA 2010-03)
CVE-2009-1571 Mozilla incorrectly frees used memory (MFSA 2010-03)
Security researcher Alin Rad Pop of Secunia Research reported that the HTML
parser incorrectly freed used memory when insufficient space was available to
process remaining input. Under such circumstances, memory occupied by in-use
objects was freed and could later be filled with attacker-controlled text.
These conditions could result in the execution or arbitrary code if methods on
the freed objects were subsequently called.
Discussion:
http://www.mozilla.org/security/announce/2010/mfsa2010-03.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0112 https://rhn.redhat.com/errata/RHSA-2010-0112.html
---
This issue has been addressed in fol
Bugzilla
CVE-2009-3884 OpenJDK zoneinfo file existence information leak (6824265)
bugzilla·2009-10-22·CVSS 5.0
CVE-2009-3884 [MEDIUM] CVE-2009-3884 OpenJDK zoneinfo file existence information leak (6824265)
CVE-2009-3884 OpenJDK zoneinfo file existence information leak (6824265)
The TimeZone.getTimeZone method allows remote attackers to probe the local
filesystem.
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2009:1560 https://rhn.redhat.com/errata/RHSA-2009-1560.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2009:1571 https://rhn.redhat.com/errata/RHSA-2009-1571.html
---
java-1.6.0-openjdk-1.6.0.0-33.b16.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/java-1.6.0-openjdk-1.6.0.0-33.b16.fc12
---
java-1.6.0-openjdk-1.6.0.0-23.b16.fc10 has been submitted as an update for Fedora 1
Bugzilla
CVE-2009-3879 OpenJDK GraphicsConfiguration information leak(6822057)
bugzilla·2009-10-22·CVSS 7.5
CVE-2009-3879 [HIGH] CVE-2009-3879 OpenJDK GraphicsConfiguration information leak(6822057)
CVE-2009-3879 OpenJDK GraphicsConfiguration information leak(6822057)
X11 and Win32GraphicsDevice don't clone arrays returned from
getConfigurations().
Therefore the list supported graphics configurations can be accessed and
modified via the elements of an array returned by getConfiguration().
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2009:1560 https://rhn.redhat.com/errata/RHSA-2009-1560.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2009:1571 https://rhn.redhat.com/errata/RHSA-2009-1571.html
---
java-1.6.0-openjdk-1.6.0.0-33.b16.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/u
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/036097.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/036132.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.htmlhttp://secunia.com/advisories/37242http://secunia.com/advisories/38770http://secunia.com/advisories/38772http://secunia.com/advisories/38847http://secunia.com/secunia_research/2009-45/http://www.debian.org/security/2010/dsa-1999http://www.mandriva.com/security/advisories?name=MDVSA-2010:042http://www.mandriva.com/security/advisories?name=MDVSA-2010:051http://www.mozilla.org/security/announce/2010/mfsa2010-03.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0112.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0113.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0153.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0154.htmlhttp://www.securityfocus.com/archive/1/509585/100/0/threadedhttp://www.ubuntu.com/usn/USN-895-1http://www.ubuntu.com/usn/USN-896-1http://www.vupen.com/english/advisories/2010/0405http://www.vupen.com/english/advisories/2010/0650https://bugzilla.mozilla.org/show_bug.cgi?id=526500https://exchange.xforce.ibmcloud.com/vulnerabilities/56361https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11227https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8615http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/036097.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/036132.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.htmlhttp://secunia.com/advisories/37242http://secunia.com/advisories/38770http://secunia.com/advisories/38772http://secunia.com/advisories/38847http://secunia.com/secunia_research/2009-45/http://www.debian.org/security/2010/dsa-1999http://www.mandriva.com/security/advisories?name=MDVSA-2010:042http://www.mandriva.com/security/advisories?name=MDVSA-2010:051http://www.mozilla.org/security/announce/2010/mfsa2010-03.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0112.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0113.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0153.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0154.htmlhttp://www.securityfocus.com/archive/1/509585/100/0/threadedhttp://www.ubuntu.com/usn/USN-895-1http://www.ubuntu.com/usn/USN-896-1http://www.vupen.com/english/advisories/2010/0405http://www.vupen.com/english/advisories/2010/0650https://bugzilla.mozilla.org/show_bug.cgi?id=526500https://exchange.xforce.ibmcloud.com/vulnerabilities/56361https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11227https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8615
2010-02-22
Published