CVE-2009-2975
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value specifying a protocol associated with an external application, which allows remote attackers to cause a denial of service (memory consumption) via vectors involving a series of function calls that set this property, as demonstrated by (1) the chromehtml: protocol and (2) the aim: protocol.
Mozilla Firefox v3.5.2 en Windows XP, en algunas situaciones posiblemente envuelvan una configuración incompleta del manejador de protocolo, no implementa apropiadamente la configuración de la propiedad document.location para un valor, especificando un protocolo asociado con una aplicación externa, lo que permite a los atacantes remotos causar una denegación de servicio (consumo de memoria) a través de un vector que envuelve una serie de llamadas a funciones que establecen esta propiedad, como se demuestra por (1) el chromehtml: protocolo y (2) el aim: protocolo.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-08-27 CVE Reserved
- 2009-08-27 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2009-08/0234.html | Mailing List | |
http://archives.neohapsis.com/archives/bugtraq/2009-08/0236.html | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/52923 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2009-08/0246.html | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 3.5.2 Search vendor "Mozilla" for product "Firefox" and version "3.5.2" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | - |
Safe
|