CVE-2009-3388
liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to "memory safety issues."
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to "memory safety issues."
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 2.65% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- mozilla/firefox · mozilla/seamonkey
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/37699Vendor Advisory
- http://secunia.com/advisories/37785Vendor Advisory
- http://secunia.com/advisories/37856
- http://secunia.com/advisories/37881
- http://securitytracker.com/id?1023335
- http://securitytracker.com/id?1023336
- http://www.mozilla.org/security/announce/2009/mfsa2009-66.htmlVendor Advisory
- http://www.novell.com/linux/security/advisories/2009_63_firefox.html
- http://www.securityfocus.com/bid/37349
- http://www.securityfocus.com/bid/37369
- http://www.ubuntu.com/usn/USN-874-1
- http://www.vupen.com/english/advisories/2009/3547Patch, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=504843
- https://bugzilla.mozilla.org/show_bug.cgi?id=523816
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54804
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8009
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00995.html
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01034.html
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01041.html
- http://secunia.com/advisories/37699Vendor Advisory
- http://secunia.com/advisories/37785Vendor Advisory
- http://secunia.com/advisories/37856
- http://secunia.com/advisories/37881
- http://securitytracker.com/id?1023335
- http://securitytracker.com/id?1023336
- http://www.mozilla.org/security/announce/2009/mfsa2009-66.htmlVendor Advisory
- http://www.novell.com/linux/security/advisories/2009_63_firefox.html
- http://www.securityfocus.com/bid/37349
- http://www.securityfocus.com/bid/37369
- http://www.ubuntu.com/usn/USN-874-1
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.