CVE-2009-2471
published 2009-07-22CVE-2009-2471: The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary…
PriorityP343critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.73%
88.7th percentile
The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.
Affected
83 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.11 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla setTimeout loses XPCNativeWrappers
vendor_redhat·2009-07-21·CVSS 10.0
CVE-2009-2471 [CRITICAL] Mozilla setTimeout loses XPCNativeWrappers
Mozilla setTimeout loses XPCNativeWrappers
The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.
GHSA
GHSA-pcxm-q3h4-prrq: The setTimeout function in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-2471 [HIGH] GHSA-pcxm-q3h4-prrq: The setTimeout function in Mozilla Firefox before 3
The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-08/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2009-1162.htmlhttp://secunia.com/advisories/35914http://secunia.com/advisories/35944http://secunia.com/advisories/36005http://secunia.com/advisories/36145http://www.mozilla.org/security/announce/2009/mfsa2009-39.htmlhttp://www.securityfocus.com/bid/35758http://www.vupen.com/english/advisories/2009/1972https://bugzilla.mozilla.org/show_bug.cgi?id=460882https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10572https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-08/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2009-1162.htmlhttp://secunia.com/advisories/35914http://secunia.com/advisories/35944http://secunia.com/advisories/36005http://secunia.com/advisories/36145http://www.mozilla.org/security/announce/2009/mfsa2009-39.htmlhttp://www.securityfocus.com/bid/35758http://www.vupen.com/english/advisories/2009/1972https://bugzilla.mozilla.org/show_bug.cgi?id=460882https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10572https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01032.html
2009-07-22
Published