Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-2044Improper Input Validation in Mozilla Firefox

Severity
4.3MEDIUMNVD
EPSS
6.0%
top 9.34%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJun 12
Latest updateMay 2

Description

Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a denial of service (application crash) via a URI for a large GIF image in the BACKGROUND attribute of a BODY element.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/firefox3.0.10
debiandebian/cairo< cairo 1.8.8-2 (bookworm)
Debiancairographics/cairo< 1.8.8-2+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-64cp-h6cw-59mg: Mozilla Firefox 32022-05-02
OSV
CVE-2009-2044: Mozilla Firefox 32009-06-12

💥Exploits & PoCs

1
Exploit-DB
Mozilla Firefox 3.0.x - Large '.GIF' File Background Denial of Service2009-05-10

📋Vendor Advisories

1
Debian
CVE-2009-2044: cairo - Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a d...2009