CVE-2009-2463
published 2009-07-22CVE-2009-2463: Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12…
PriorityP339critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.43%
92.9th percentile
Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger buffer overflows.
Affected
112 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nspr | < nspr 4.8.2-1 (bookworm) | nspr 4.8.2-1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-483p-23q4-52hc: Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64
ghsa_unreviewed·2022-05-02
CVE-2009-2463 [HIGH] GHSA-483p-23q4-52hc: Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64
Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger buffer overflows.
OSV
CVE-2009-2463: Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64
osv·2009-07-22·CVSS 10.0
CVE-2009-2463 [CRITICAL] CVE-2009-2463: Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64
Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger buffer overflows.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2010-03-18·CVSS 6.8
CVE-2009-0689 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Several flaws were discovered in the JavaScript engine of Thunderbird. If a
user had JavaScript enabled and were tricked into viewing malicious web
content, a remote attacker could cause a denial of service or possibly
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2009-0689, CVE-2009-2463, CVE-2009-3075)
Josh Soref discovered that the BinHex decoder used in Thunderbird contained
a flaw. If a user were tricked into viewing malicious content, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-3072)
It was discovered that Thunderbird did not properly manage memory when
using XUL tree el
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-07-22·CVSS 10.0
CVE-2009-2462 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Several flaws were discovered in the Firefox browser and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-2462,
CVE-2009-2463, CVE-2009-2464, CVE-2009-2465, CVE-2009-2466, CVE-2009-2469)
Attila Suszter discovered a flaw in the way Firefox processed Flash content.
If a user were tricked into viewing and navigating within a specially
crafted Flash object, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2009-2467)
It was discovere
Red Hat
Mozilla Base64 decoding crash
vendor_redhat·2009-07-21·CVSS 10.0
CVE-2009-2463 [CRITICAL] Mozilla Base64 decoding crash
Mozilla Base64 decoding crash
Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger buffer overflows.
Debian
CVE-2009-2463: nspr - Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode fu...
vendor_debian·2009·CVSS 10.0
CVE-2009-2463 [CRITICAL] CVE-2009-2463: nspr - Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode fu...
Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger buffer overflows.
Scope: local
bookworm: resolved (fixed in 4.8.2-1)
bullseye: resolved (fixed in 4.8.2-1)
forky: resolved (fixed in 4.8.2-1)
sid: resolved (fixed in 4.8.2-1)
trixie: resolved (fixed in 4.8.2-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-08/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2009-1162.htmlhttp://rhn.redhat.com/errata/RHSA-2009-1163.htmlhttp://secunia.com/advisories/35914http://secunia.com/advisories/35943http://secunia.com/advisories/35944http://secunia.com/advisories/35947http://secunia.com/advisories/36005http://secunia.com/advisories/36145http://secunia.com/advisories/38977http://secunia.com/advisories/39001http://sunsolve.sun.com/search/document.do?assetkey=1-26-265068-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020800.1-1http://www.mozilla.org/security/announce/2009/mfsa2009-34.htmlhttp://www.mozilla.org/security/announce/2010/mfsa2010-07.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0153.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0154.htmlhttp://www.securityfocus.com/bid/35758http://www.ubuntu.com/usn/USN-915-1http://www.vupen.com/english/advisories/2009/1972http://www.vupen.com/english/advisories/2009/2152http://www.vupen.com/english/advisories/2010/0648http://www.vupen.com/english/advisories/2010/0650https://bugzilla.mozilla.org/show_bug.cgi?id=492779https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10369https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-08/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2009-1162.htmlhttp://rhn.redhat.com/errata/RHSA-2009-1163.htmlhttp://secunia.com/advisories/35914http://secunia.com/advisories/35943http://secunia.com/advisories/35944http://secunia.com/advisories/35947http://secunia.com/advisories/36005http://secunia.com/advisories/36145http://secunia.com/advisories/38977http://secunia.com/advisories/39001http://sunsolve.sun.com/search/document.do?assetkey=1-26-265068-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020800.1-1http://www.mozilla.org/security/announce/2009/mfsa2009-34.htmlhttp://www.mozilla.org/security/announce/2010/mfsa2010-07.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0153.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0154.htmlhttp://www.securityfocus.com/bid/35758http://www.ubuntu.com/usn/USN-915-1http://www.vupen.com/english/advisories/2009/1972http://www.vupen.com/english/advisories/2009/2152http://www.vupen.com/english/advisories/2010/0648http://www.vupen.com/english/advisories/2010/0650https://bugzilla.mozilla.org/show_bug.cgi?id=492779https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10369https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01032.html
2009-07-22
Published