CVE-2009-3070
published 2009-09-10CVE-2009-3070: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory…
PriorityP434critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.45%
91.9th percentile
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Affected
93 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.13 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-09-10·CVSS 10.0
CVE-2009-3070 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Several flaws were discovered in the Firefox browser and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-3070,
CVE-2009-3071, CVE-2009-3072, CVE-2009-3074, CVE-2009-3075)
Jesse Ruderman and Dan Kaminsky discovered that Firefox did not adequately
inform users when security modules were added or removed via PKCS11. If
a user visited a malicious website, an attacker could exploit this to
trick the user into installing a malicious PKCS11 module. (CVE-2009-3076)
It was discovered that Firefox did not properly manage memory wh
Red Hat
Firefox 3.5 3.0.14 browser engine crashes
vendor_redhat·2009-09-09·CVSS 10.0
CVE-2009-3070 [CRITICAL] Firefox 3.5 3.0.14 browser engine crashes
Firefox 3.5 3.0.14 browser engine crashes
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
GHSA
GHSA-hx9x-3jpr-5g63: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-3070 [HIGH] GHSA-hx9x-3jpr-5g63: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/36670http://secunia.com/advisories/36671http://secunia.com/advisories/36692http://secunia.com/advisories/37098http://www.debian.org/security/2009/dsa-1885http://www.mozilla.org/security/announce/2009/mfsa2009-47.htmlhttp://www.novell.com/linux/security/advisories/2009_48_firefox.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1430.htmlhttp://www.securityfocus.com/bid/36343https://bugzilla.mozilla.org/show_bug.cgi?id=430569https://bugzilla.mozilla.org/show_bug.cgi?id=437565https://bugzilla.mozilla.org/show_bug.cgi?id=465651https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11702https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6073http://secunia.com/advisories/36670http://secunia.com/advisories/36671http://secunia.com/advisories/36692http://secunia.com/advisories/37098http://www.debian.org/security/2009/dsa-1885http://www.mozilla.org/security/announce/2009/mfsa2009-47.htmlhttp://www.novell.com/linux/security/advisories/2009_48_firefox.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1430.htmlhttp://www.securityfocus.com/bid/36343https://bugzilla.mozilla.org/show_bug.cgi?id=430569https://bugzilla.mozilla.org/show_bug.cgi?id=437565https://bugzilla.mozilla.org/show_bug.cgi?id=465651https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11702https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6073
2009-09-10
Published