CVE-2009-2462
The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) the frame chain and…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) the frame chain and synchronous events, (2) a SetMayHaveFrame assertion and nsCSSFrameConstructor::CreateFloatingLetterFrame, (3) nsCSSFrameConstructor::ConstructFrame, (4) the child list and initial reflow, (5) GetLastSpecialSibling, (6) nsFrameManager::GetPrimaryFrameFor and MathML, (7) nsFrame::GetBoxAscent, (8) nsCSSFrameConstructor::AdjustParentFrame, (9) nsDOMOfflineResourceList, and (10) nsContentUtils::ComparePosition.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 5.41% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- mozilla/firefox · mozilla/thunderbird
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00002.html
- http://rhn.redhat.com/errata/RHSA-2009-1162.html
- http://rhn.redhat.com/errata/RHSA-2009-1163.html
- http://secunia.com/advisories/35914Vendor Advisory
- http://secunia.com/advisories/35943Vendor Advisory
- http://secunia.com/advisories/35944Vendor Advisory
- http://secunia.com/advisories/35947Vendor Advisory
- http://secunia.com/advisories/36005
- http://secunia.com/advisories/36145
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-265068-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020800.1-1
- http://www.mozilla.org/security/announce/2009/mfsa2009-34.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0153.html
- http://www.redhat.com/support/errata/RHSA-2010-0154.html
- http://www.securityfocus.com/bid/35758Patch
- http://www.vupen.com/english/advisories/2009/1972Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2152
- http://www.vupen.com/english/advisories/2010/0650
- https://bugzilla.mozilla.org/show_bug.cgi?id=413085
- https://bugzilla.mozilla.org/show_bug.cgi?id=442227
- https://bugzilla.mozilla.org/show_bug.cgi?id=445177
- https://bugzilla.mozilla.org/show_bug.cgi?id=461861
- https://bugzilla.mozilla.org/show_bug.cgi?id=463350
- https://bugzilla.mozilla.org/show_bug.cgi?id=466763
- https://bugzilla.mozilla.org/show_bug.cgi?id=468211
- https://bugzilla.mozilla.org/show_bug.cgi?id=472668
- https://bugzilla.mozilla.org/show_bug.cgi?id=472950
- https://bugzilla.mozilla.org/show_bug.cgi?id=491134
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10906
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.