CVE-2009-1832
Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors involving "double frame…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors involving "double frame construction."
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 9.18% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird
- Source
- secalert@redhat.com
References
- http://osvdb.org/55148
- http://secunia.com/advisories/35331Vendor Advisory
- http://secunia.com/advisories/35415
- http://secunia.com/advisories/35431Vendor Advisory
- http://secunia.com/advisories/35439Vendor Advisory
- http://secunia.com/advisories/35440Vendor Advisory
- http://secunia.com/advisories/35468
- http://secunia.com/advisories/35561
- http://secunia.com/advisories/35602
- http://secunia.com/advisories/35882
- http://securitytracker.com/id?1022376Patch
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-265068-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020800.1-1
- http://www.debian.org/security/2009/dsa-1820
- http://www.debian.org/security/2009/dsa-1830
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:141
- http://www.mozilla.org/security/announce/2009/mfsa2009-24.htmlVendor Advisory
- http://www.securityfocus.com/bid/35326
- http://www.securityfocus.com/bid/35371
- http://www.securitytracker.com/id?1022397
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.454275
- http://www.vupen.com/english/advisories/2009/1572Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2152
- https://bugzilla.mozilla.org/show_bug.cgi?id=484031Exploit
- https://bugzilla.redhat.com/show_bug.cgi?id=503569Exploit
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10237
- https://rhn.redhat.com/errata/RHSA-2009-1095.htmlPatch, Vendor Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.