CVE-2009-2462
Summary
| CVE | CVE-2009-2462 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-07-22 18:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) the frame chain and synchronous events, (2) a SetMayHaveFrame assertion and nsCSSFrameConstructor::CreateFloatingLetterFrame, (3) nsCSSFrameConstructor::ConstructFrame, (4) the child list and initial reflow, (5) GetLastSpecialSibling, (6) nsFrameManager::GetPrimaryFrameFor and MathML, (7) nsFrame::GetBoxAscent, (8) nsCSSFrameConstructor::AdjustParentFrame, (9) nsDOMOfflineResourceList, and (10) nsContentUtils::ComparePosition. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox | 0.1 | All | All | All |
| Application | Mozilla | Firefox | 0.10 | All | All | All |
| Application | Mozilla | Firefox | 0.10.1 | All | All | All |
| Application | Mozilla | Firefox | 0.2 | All | All | All |
| Application | Mozilla | Firefox | 0.3 | All | All | All |
| Application | Mozilla | Firefox | 0.4 | All | All | All |
| Application | Mozilla | Firefox | 0.5 | All | All | All |
| Application | Mozilla | Firefox | 0.6 | All | All | All |
| Application | Mozilla | Firefox | 0.6.1 | All | All | All |
| Application | Mozilla | Firefox | 0.7 | All | All | All |
| Application | Mozilla | Firefox | 0.7.1 | All | All | All |
| Application | Mozilla | Firefox | 0.8 | All | All | All |
| Application | Mozilla | Firefox | 0.9 | All | All | All |
| Application | Mozilla | Firefox | 0.9 | rc | All | All |
| Application | Mozilla | Firefox | 0.9.1 | All | All | All |
| Application | Mozilla | Firefox | 0.9.2 | All | All | All |
| Application | Mozilla | Firefox | 0.9.3 | All | All | All |
| Application | Mozilla | Firefox | 0.9_rc | All | All | All |
| Application | Mozilla | Firefox | 1.0 | All | All | All |
| Application | Mozilla | Firefox | 1.0 | preview_release | All | All |
| Application | Mozilla | Firefox | 1.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.0.4 | All | All | All |
| Application | Mozilla | Firefox | 1.0.5 | All | All | All |
| Application | Mozilla | Firefox | 1.0.6 | All | All | All |
| Application | Mozilla | Firefox | 1.0.6 | All | linux | All |
| Application | Mozilla | Firefox | 1.0.7 | All | All | All |
| Application | Mozilla | Firefox | 1.0.8 | All | All | All |
| Application | Mozilla | Firefox | 1.4.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5 | beta1 | All | All |
| Application | Mozilla | Firefox | 1.5 | beta2 | All | All |
| Application | Mozilla | Firefox | 1.5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.10 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.11 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.12 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.4 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.6 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.7 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.8 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.9 | All | All | All |
| Application | Mozilla | Firefox | 1.5.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5.2 | All | All | All |
| Application | Mozilla | Firefox | 1.5.3 | All | All | All |
| Application | Mozilla | Firefox | 1.5.4 | All | All | All |
| Application | Mozilla | Firefox | 1.5.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.6 | All | All | All |
| Application | Mozilla | Firefox | 1.5.7 | All | All | All |
| Application | Mozilla | Firefox | 1.5.8 | All | All | All |
| Application | Mozilla | Firefox | 1.8 | All | All | All |
| Application | Mozilla | Firefox | 2.0 | All | All | All |
| Application | Mozilla | Firefox | 2.0 | beta1 | All | All |
| Application | Mozilla | Firefox | 2.0 | beta_1 | All | All |
| Application | Mozilla | Firefox | 2.0 | rc2 | All | All |
| Application | Mozilla | Firefox | 2.0 | rc3 | All | All |
| Application | Mozilla | Firefox | 2.0.0.1 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.10 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.11 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.12 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.13 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.14 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.15 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.16 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.17 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.18 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.19 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.2 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.20 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.21 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.3 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.4 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.5 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.6 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.7 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.8 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.9 | All | All | All |
| Application | Mozilla | Firefox | 2.0_.1 | All | All | All |
| Application | Mozilla | Firefox | 2.0_.10 | All | All | All |
| Application | Mozilla | Firefox | 2.0_.4 | All | All | All |
| Application | Mozilla | Firefox | 2.0_.5 | All | All | All |
| Application | Mozilla | Firefox | 2.0_.6 | All | All | All |
| Application | Mozilla | Firefox | 2.0_.7 | All | All | All |
| Application | Mozilla | Firefox | 2.0_.9 | All | All | All |
| Application | Mozilla | Firefox | 2.0_8 | All | All | All |
| Application | Mozilla | Firefox | 3.0 | All | All | All |
| Application | Mozilla | Firefox | 3.0 | alpha | All | All |
| Application | Mozilla | Firefox | 3.0 | beta2 | All | All |
| Application | Mozilla | Firefox | 3.0 | beta5 | All | All |
| Application | Mozilla | Firefox | 3.0.1 | All | All | All |
| Application | Mozilla | Firefox | 3.0.10 | All | All | All |
| Application | Mozilla | Firefox | 3.0.2 | All | All | All |
| Application | Mozilla | Firefox | 3.0.3 | All | All | All |
| Application | Mozilla | Firefox | 3.0.4 | All | All | All |
| Application | Mozilla | Firefox | 3.0.5 | All | All | All |
| Application | Mozilla | Firefox | 3.0.6 | All | All | All |
| Application | Mozilla | Firefox | 3.0.7 | All | All | All |
| Application | Mozilla | Firefox | 3.0.8 | All | All | All |
| Application | Mozilla | Firefox | 3.0.9 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.0 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.11 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.12 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.13 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.14 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.15 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.16 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.17 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.18 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.19 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.20 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.21 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.3 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.4 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.5 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.6 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.7 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.8 | All | All | All |
| Application | Mozilla | Thunderbird | 2.0.0.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 461861 – Set aside the frame chain when firing synchronous events | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 468211 – Crash [@ nsCSSFrameConstructor::AdjustParentFrame] with DOMAttrModified, observes, binding and focusing | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| Security Advisory SA36145 - SUSE update for MozillaFirefox - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 10 Update: google-gadgets-0.10.5-8.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| 445177 – Crash [@ nsContentUtils::ComparePosition(nsINode*, nsINode*) ] with multipe identic ids | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 413085 – "ASSERTION: SetMayHaveFrame failed" and crash [@ nsCSSFrameConstructor::CreateFloatingLetterFrame] with Arabic, floating first-letter | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Mozilla Firefox Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Support | Red Hat | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [security-announce] SUSE Security Announcement: Mozilla Firefox 3.0.12 ( | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| 472950 – "ASSERTION: child list is not empty for initial reflow" with :first-letter, rtl, pre | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 463350 – Crash [@ GetLastSpecialSibling] with -moz-column, fieldset, select | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| MFSA 2009-34: Crashes with evidence of memory corruption (rv:1.9.1/1.9.0.12) | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Patch, Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Red Hat update for firefox - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [security-announce] SUSE Security Announcement: Mozilla Firefox 3.0 (SUS | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| SUSE update for MozillaFirefox - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| access.redhat.com | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| 472668 – Crash [@ nsFrame::GetBoxAscent] with binding, observes and DOMAttrModified | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Red Hat update for seamonkey - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 491134 – nsDOMOfflineResourceList uses its own (unsafe) way to dispatch events | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| RETIRED: Mozilla Firefox MFSA 2009-34, -35, -36, -37, -39, -40 Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Mozilla Thunderbird Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 442227 – Crash [@ nsFrameManager::GetPrimaryFrameFor] with mathml, DOMAttrModified doing stuff | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| 466763 – Crash [@ nsCSSFrameConstructor::ConstructFrame] with RTL, floating first-letter | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.