js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.
References
Configurations
History
21 Nov 2024, 01:04
Type | Values Removed | Values Added |
---|---|---|
References | () http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/ - | |
References | () http://isc.sans.org/diary.html?storyid=6796 - | |
References | () http://secunia.com/advisories/35798 - Vendor Advisory | |
References | () http://sunsolve.sun.com/search/document.do?assetkey=1-66-266148-1 - | |
References | () http://voices.washingtonpost.com/securityfix/2009/07/stopgap_fix_for_critical_firef.html - | |
References | () http://www.exploit-db.com/exploits/9137 - | |
References | () http://www.exploit-db.com/exploits/9181 - | |
References | () http://www.h-online.com/security/First-Zero-Day-Exploit-for-Firefox-3-5--/news/113761 - | |
References | () http://www.kb.cert.org/vuls/id/443060 - US Government Resource | |
References | () http://www.mozilla.org/security/announce/2009/mfsa2009-41.html - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/35660 - Exploit | |
References | () http://www.vupen.com/english/advisories/2009/1868 - Patch, Vendor Advisory | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=503286 - | |
References | () https://www.exploit-db.com/exploits/40936/ - | |
References | () https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00909.html - |
Information
Published : 2009-07-15 15:30
Updated : 2024-11-21 01:04
NVD link : CVE-2009-2477
Mitre link : CVE-2009-2477
CVE.ORG link : CVE-2009-2477
JSON object : View
Products Affected
mozilla
- firefox
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')