CVE-2009-2477
Summary
| CVE | CVE-2009-2477 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-07-15 15:30:01 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Exploit – Page 40936 – Exploits Database | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Mozilla Firefox 3.5 (Font tags) Remote Heap Spray Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Firefox 3.5 new exploit - confirmed | af854a3a-2127-422b-91ae-364da2661108 | isc.sans.org | |
| Critical JavaScript vulnerability in Firefox 3.5 at Mozilla Security Blog | af854a3a-2127-422b-91ae-364da2661108 | blog.mozilla.com | |
| #266148: Multiple Security Vulnerabilities in Firefox Versions Prior to 3.5.2 May Allow Execution of Arbitrary Code or Application Crash | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| [SECURITY] Fedora 11 Update: gnome-python2-extras-2.25.3-5.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Mozilla Firefox Two Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| MFSA 2009-41: Corrupt JIT state after deep return from native function | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Patch, Vendor Advisory |
| Mozilla Firefox 3.5 (Font tags) Remote Buffer Overflow Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Bug 503286 – browser crash when search suggestions show [@ js_Interpret ] [@ js_Execute] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| US-CERT Vulnerability Note VU#443060 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Security Fix - Stopgap Fix for Critical Firefox 3.5 Security Hole | af854a3a-2127-422b-91ae-364da2661108 | voices.washingtonpost.com | |
| First Zero Day Exploit for Firefox 3.5 - The H Security: News and Features | af854a3a-2127-422b-91ae-364da2661108 | www.h-online.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| Mozilla Firefox 3.5 'TraceMonkey' Component Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.