CVE-2009-2975
Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value specifying a protocol associated with an external…
Does this matter?
Lower severity and a low EPSS score (2.05%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value specifying a protocol associated with an external application, which allows remote attackers to cause a denial of service (memory consumption) via vectors involving a series of function calls that set this property, as demonstrated by (1) the chromehtml: protocol and (2) the aim: protocol.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 2.05% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/firefox
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2009-08/0234.html
- http://archives.neohapsis.com/archives/bugtraq/2009-08/0236.html
- http://archives.neohapsis.com/archives/bugtraq/2009-08/0246.htmlExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52923
- http://archives.neohapsis.com/archives/bugtraq/2009-08/0234.html
- http://archives.neohapsis.com/archives/bugtraq/2009-08/0236.html
- http://archives.neohapsis.com/archives/bugtraq/2009-08/0246.htmlExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52923
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.