CVE-2009-1837
Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transition during Java applet loading,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transition during Java applet loading, related to a use-after-free vulnerability for memory associated with a destroyed Java object.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 4.33% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362, CWE-416
- Affected
- mozilla/firefox · debian/debian linux · fedoraproject/fedora · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/34241Broken Link, Vendor Advisory
- http://secunia.com/advisories/35331Broken Link, Vendor Advisory
- http://secunia.com/advisories/35415Broken Link
- http://secunia.com/advisories/35431Broken Link, Vendor Advisory
- http://secunia.com/advisories/35468Broken Link
- http://secunia.com/secunia_research/2009-19/Broken Link, Vendor Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1Broken Link
- http://www.debian.org/security/2009/dsa-1820Mailing List, Third Party Advisory
- http://www.mozilla.org/security/announce/2009/mfsa2009-28.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/504260/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35326Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35360Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1022386Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/1572Broken Link, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=486269Exploit, Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=503579Issue Tracking
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10628Broken Link
- https://rhn.redhat.com/errata/RHSA-2009-1095.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.htmlMailing List
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.htmlMailing List
- http://secunia.com/advisories/34241Broken Link, Vendor Advisory
- http://secunia.com/advisories/35331Broken Link, Vendor Advisory
- http://secunia.com/advisories/35415Broken Link
- http://secunia.com/advisories/35431Broken Link, Vendor Advisory
- http://secunia.com/advisories/35468Broken Link
- http://secunia.com/secunia_research/2009-19/Broken Link, Vendor Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1Broken Link
- http://www.debian.org/security/2009/dsa-1820Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.