CVE-2009-2465
published 2009-07-22CVE-2009-2465: Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute…
PriorityP433critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.41%
91.8th percentile
Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving double frame construction, related to (1) nsHTMLContentSink.cpp, (2) nsXMLContentSink.cpp, and (3) nsPresShell.cpp, and the nsSubDocumentFrame::Reflow function.
Affected
104 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.11 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7x2r-cg6w-8rwf: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-2465 [HIGH] GHSA-7x2r-cg6w-8rwf: Mozilla Firefox before 3
Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving double frame construction, related to (1) nsHTMLContentSink.cpp, (2) nsXMLContentSink.cpp, and (3) nsPresShell.cpp, and the nsSubDocumentFrame::Reflow function.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-07-22·CVSS 10.0
CVE-2009-2462 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Several flaws were discovered in the Firefox browser and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-2462,
CVE-2009-2463, CVE-2009-2464, CVE-2009-2465, CVE-2009-2466, CVE-2009-2469)
Attila Suszter discovered a flaw in the way Firefox processed Flash content.
If a user were tricked into viewing and navigating within a specially
crafted Flash object, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2009-2467)
It was discovere
Red Hat
Mozilla double frame construction crashes
vendor_redhat·2009-07-21·CVSS 10.0
CVE-2009-2465 [CRITICAL] Mozilla double frame construction crashes
Mozilla double frame construction crashes
Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving double frame construction, related to (1) nsHTMLContentSink.cpp, (2) nsXMLContentSink.cpp, and (3) nsPresShell.cpp, and the nsSubDocumentFrame::Reflow function.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-08/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2009-1162.htmlhttp://secunia.com/advisories/35914http://secunia.com/advisories/35943http://secunia.com/advisories/35944http://secunia.com/advisories/36005http://secunia.com/advisories/36145http://sunsolve.sun.com/search/document.do?assetkey=1-26-265068-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020800.1-1http://www.mozilla.org/security/announce/2009/mfsa2009-34.htmlhttp://www.securityfocus.com/bid/35758http://www.vupen.com/english/advisories/2009/1972http://www.vupen.com/english/advisories/2009/2152https://bugzilla.mozilla.org/show_bug.cgi?id=482578https://bugzilla.mozilla.org/show_bug.cgi?id=489050https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10402https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-08/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2009-1162.htmlhttp://secunia.com/advisories/35914http://secunia.com/advisories/35943http://secunia.com/advisories/35944http://secunia.com/advisories/36005http://secunia.com/advisories/36145http://sunsolve.sun.com/search/document.do?assetkey=1-26-265068-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020800.1-1http://www.mozilla.org/security/announce/2009/mfsa2009-34.htmlhttp://www.securityfocus.com/bid/35758http://www.vupen.com/english/advisories/2009/1972http://www.vupen.com/english/advisories/2009/2152https://bugzilla.mozilla.org/show_bug.cgi?id=482578https://bugzilla.mozilla.org/show_bug.cgi?id=489050https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10402https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01032.html
2009-07-22
Published