CVE-2009-2477
Naenara Browser 3.5 (RedStar 3.0 Desktop) - 'JACKRABBIT' Client-Side Command Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
7Exploited in Wild
-Decision
Descriptions
js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.
El archivo js/src/jstracer.cpp en el compilador JavaScript Just-in-Time (JIT) (también se conoce como TraceMonkey) en Firefox de Mozilla versiones 3.5 anteriores a 3.5.1, permite a los atacantes remotos ejecutar código arbitrario por medio de cierto uso de la función escape que desencadena el acceso a ubicaciones de memoria no inicializadas, como es demostrado originalmente por un documento que contiene elementos P y FONT.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-07-13 First Exploit
- 2009-07-15 CVE Reserved
- 2009-07-15 CVE Published
- 2024-08-07 CVE Updated
- 2025-02-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (18)
URL | Tag | Source |
---|---|---|
http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35 | X_refsource_confirm | |
http://isc.sans.org/diary.html?storyid=6796 | X_refsource_misc | |
http://voices.washingtonpost.com/securityfix/2009/07/stopgap_fix_for_critical_firef.html | X_refsource_misc | |
http://www.h-online.com/security/First-Zero-Day-Exploit-for-Firefox-3-5--/news/113761 | X_refsource_misc | |
http://www.kb.cert.org/vuls/id/443060 | Third Party Advisory |
|
https://bugzilla.mozilla.org/show_bug.cgi?id=503286 | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/40936 | 2024-08-07 | |
https://www.exploit-db.com/exploits/16299 | 2010-09-20 | |
https://www.exploit-db.com/exploits/9214 | 2009-07-20 | |
https://www.exploit-db.com/exploits/9137 | 2009-07-13 | |
http://www.exploit-db.com/exploits/9137 | 2024-08-07 | |
http://www.exploit-db.com/exploits/9181 | 2024-08-07 | |
http://www.securityfocus.com/bid/35660 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://www.mozilla.org/security/announce/2009/mfsa2009-41.html | 2017-09-19 | |
http://www.vupen.com/english/advisories/2009/1868 | 2017-09-19 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/35798 | 2017-09-19 | |
http://sunsolve.sun.com/search/document.do?assetkey=1-66-266148-1 | 2017-09-19 | |
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00909.html | 2017-09-19 |