Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-2535Mozilla Firefox vulnerability

6 documents6 sources
Severity
5.0MEDIUMNVD
CNA7.1
EPSS
8.2%
top 7.76%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 20
Latest updateMay 2

Description

Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/firefox2.0.0.18+72
NVDmozilla/thunderbird2.0.0.18+66
NVDmozilla/seamonkey31 versions+30

🔴Vulnerability Details

2
GHSA
GHSA-75jf-fx6q-2qjm: Mozilla Firefox before 22022-05-02
CVEList
CVE-2009-2535: Mozilla Firefox before 22009-07-20

💥Exploits & PoCs

1
Exploit-DB
Multiple Browsers - Denial of Service2009-07-15

📋Vendor Advisories

1
Red Hat
Thunderbird: DoS via large length property of a Select object2009-07-15

💬Community

1
Bugzilla
CVE-2009-2535 Firefox, SeaMonkey, Thunderbird: DoS via large length property of a Select object2009-07-21
CVE-2009-2535 — Mozilla Firefox vulnerability | cvebase