CVE-2009-3978
published 2009-11-19CVE-2009-3978: The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of…
PriorityP414medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.79%
76.2th percentile
The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.
Affected
66 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.5.4 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Seamonkey: NULL pointer dereference in GIF decoder
vendor_redhat·2009-10-29·CVSS 10.0
CVE-2009-3978 [CRITICAL] CWE-476 Seamonkey: NULL pointer dereference in GIF decoder
Seamonkey: NULL pointer dereference in GIF decoder
The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.
GHSA
GHSA-8w37-959h-v45j: The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2
ghsa_unreviewed·2022-05-02·CVSS 10.0
CVE-2009-3978 [CRITICAL] GHSA-8w37-959h-v45j: The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2
The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.
No detection rules found.
No public exploits indexed.
http://hg.mozilla.org/releases/mozilla-1.9.1/rev/edf189567edchttp://www.h-online.com/open/news/item/Mozilla-fixes-critical-bugs-with-Firefox-3-5-5-852070.htmlhttp://www.mozilla.com/en-US/firefox/3.5.5/releasenotes/https://bugzilla.mozilla.org/show_bug.cgi?id=525326https://wiki.mozilla.org/Releases/Firefox_3.5.5/Test_Planhttp://hg.mozilla.org/releases/mozilla-1.9.1/rev/edf189567edchttp://www.h-online.com/open/news/item/Mozilla-fixes-critical-bugs-with-Firefox-3-5-5-852070.htmlhttp://www.mozilla.com/en-US/firefox/3.5.5/releasenotes/https://bugzilla.mozilla.org/show_bug.cgi?id=525326https://wiki.mozilla.org/Releases/Firefox_3.5.5/Test_Plan
2009-11-19
Published