CVE-2009-3981
published 2009-12-17CVE-2009-3981: Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a…
critical9.3CVSS 3.1
AVNACMAuNCCICAC
Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Affected
130 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.15 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
GHSA
GHSA-3rf9-fc8c-hj8h: Unspecified vulnerability in the browser engine in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-3981 [HIGH] GHSA-3rf9-fc8c-hj8h: Unspecified vulnerability in the browser engine in Mozilla Firefox before 3
Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Ubuntu
Firefox 3.0 and Xulrunner 1.9 regression
vendor_ubuntu·2010-01-08·CVSS 9.3
[CRITICAL] Firefox 3.0 and Xulrunner 1.9 regression
Title: Firefox 3.0 and Xulrunner 1.9 regression
Summary: Firefox 3.0 and Xulrunner 1.9 regression
USN-873-1 fixed vulnerabilities in Firefox and Xulrunner. The upstream
changes introduced a regression when using NTLM authentication. This update
fixes the problem and adds additional stability fixes.
We apologize for the inconvenience.
Original advisory details:
Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and
David James discovered several flaws in the browser and JavaScript engines
of Firefox. If a user were tricked into viewing a malicious website, a
remote attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2009-3979, CVE-2009-3981, CVE-2009-3986)
Takehiro Takahashi discovere
Ubuntu
Firefox 3.0 and Xulrunner 1.9 vulnerabilities
vendor_ubuntu·2009-12-18·CVSS 9.3
CVE-2009-3979 [CRITICAL] Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Title: Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Summary: Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and
David James discovered several flaws in the browser and JavaScript engines
of Firefox. If a user were tricked into viewing a malicious website, a
remote attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2009-3979, CVE-2009-3981, CVE-2009-3986)
Takehiro Takahashi discovered flaws in the NTLM implementation in Firefox.
If an NTLM authenticated user visited a malicious website, a remote
attacker could send requests to other applications, authenticated as the
user. (CVE-2009-3983)
Jonathan Morgan discovered that Firefox did not
Red Hat
Mozilla crashes with evidence of memory corruption
vendor_redhat·2009-12-15·CVSS 9.3
CVE-2009-3981 [CRITICAL] Mozilla crashes with evidence of memory corruption
Mozilla crashes with evidence of memory corruption
Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/37699http://secunia.com/advisories/37704http://secunia.com/advisories/37785http://secunia.com/advisories/37813http://secunia.com/advisories/37881http://securitytracker.com/id?1023333http://securitytracker.com/id?1023334http://www.debian.org/security/2009/dsa-1956http://www.mozilla.org/security/announce/2009/mfsa2009-65.htmlhttp://www.novell.com/linux/security/advisories/2009_63_firefox.htmlhttp://www.securityfocus.com/bid/37349http://www.securityfocus.com/bid/37363http://www.ubuntu.com/usn/USN-873-1http://www.vupen.com/english/advisories/2009/3547https://bugzilla.mozilla.org/show_bug.cgi?id=468771https://bugzilla.redhat.com/show_bug.cgi?id=546713https://exchange.xforce.ibmcloud.com/vulnerabilities/54801https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8523https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8584https://rhn.redhat.com/errata/RHSA-2009-1674.htmlhttp://secunia.com/advisories/37699http://secunia.com/advisories/37704http://secunia.com/advisories/37785http://secunia.com/advisories/37813http://secunia.com/advisories/37881http://securitytracker.com/id?1023333http://securitytracker.com/id?1023334http://www.debian.org/security/2009/dsa-1956http://www.mozilla.org/security/announce/2009/mfsa2009-65.htmlhttp://www.novell.com/linux/security/advisories/2009_63_firefox.htmlhttp://www.securityfocus.com/bid/37349http://www.securityfocus.com/bid/37363http://www.ubuntu.com/usn/USN-873-1http://www.vupen.com/english/advisories/2009/3547https://bugzilla.mozilla.org/show_bug.cgi?id=468771https://bugzilla.redhat.com/show_bug.cgi?id=546713https://exchange.xforce.ibmcloud.com/vulnerabilities/54801https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8523https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8584https://rhn.redhat.com/errata/RHSA-2009-1674.html
2009-12-17
Published