{"api_version":"1","generated_at":"2026-07-24T19:37:20+00:00","cve":"CVE-2009-2477","urls":{"html":"https://cve.report/CVE-2009-2477","api":"https://cve.report/api/cve/CVE-2009-2477.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-2477","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-2477"},"summary":{"title":"CVE-2009-2477","description":"js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-07-15 15:30:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-94","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://www.exploit-db.com/exploits/40936/","name":"https://www.exploit-db.com/exploits/40936/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Exploit – Page 40936 – Exploits Database","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.exploit-db.com/exploits/9181","name":"http://www.exploit-db.com/exploits/9181","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mozilla Firefox 3.5 (Font tags) Remote Heap Spray Exploit","mime":"text/x-python","httpstatus":"200","archivestatus":"200"},{"url":"http://isc.sans.org/diary.html?storyid=6796","name":"http://isc.sans.org/diary.html?storyid=6796","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Firefox 3.5 new exploit - confirmed","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/","name":"http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Critical JavaScript vulnerability in Firefox 3.5  at  Mozilla Security Blog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-266148-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-266148-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#266148: Multiple Security Vulnerabilities in Firefox Versions Prior to 3.5.2 May Allow Execution of Arbitrary Code or Application Crash","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00909.html","name":"https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00909.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] Fedora 11 Update: gnome-python2-extras-2.25.3-5.fc11","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/35798","name":"http://secunia.com/advisories/35798","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Mozilla Firefox Two Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2009/mfsa2009-41.html","name":"http://www.mozilla.org/security/announce/2009/mfsa2009-41.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"MFSA 2009-41: Corrupt JIT state after deep return from native function","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.exploit-db.com/exploits/9137","name":"http://www.exploit-db.com/exploits/9137","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mozilla Firefox 3.5 (Font tags) Remote Buffer Overflow Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=503286","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=503286","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug 503286 – browser crash when search suggestions show [@ js_Interpret ] [@ js_Execute]","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/443060","name":"http://www.kb.cert.org/vuls/id/443060","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#443060","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://voices.washingtonpost.com/securityfix/2009/07/stopgap_fix_for_critical_firef.html","name":"http://voices.washingtonpost.com/securityfix/2009/07/stopgap_fix_for_critical_firef.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Fix\n - Stopgap Fix for Critical Firefox 3.5 Security Hole","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.h-online.com/security/First-Zero-Day-Exploit-for-Firefox-3-5--/news/113761","name":"http://www.h-online.com/security/First-Zero-Day-Exploit-for-Firefox-3-5--/news/113761","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"First Zero Day Exploit for Firefox 3.5 - The H Security: News and Features","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/1868","name":"http://www.vupen.com/english/advisories/2009/1868","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/35660","name":"http://www.securityfocus.com/bid/35660","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Mozilla Firefox 3.5 'TraceMonkey' Component Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-2477","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-2477","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"2477","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"3.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:52:14.977Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=503286"},{"name":"VU#443060","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/443060"},{"name":"FEDORA-2009-7898","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00909.html"},{"name":"40936","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/40936/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://voices.washingtonpost.com/securityfix/2009/07/stopgap_fix_for_critical_firef.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://isc.sans.org/diary.html?storyid=6796"},{"name":"266148","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-266148-1"},{"name":"35660","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/35660"},{"name":"9181","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/9181"},{"name":"35798","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35798"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/"},{"name":"ADV-2009-1868","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/1868"},{"name":"9137","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/9137"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.h-online.com/security/First-Zero-Day-Exploit-for-Firefox-3-5--/news/113761"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/2009/mfsa2009-41.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-07-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=503286"},{"name":"VU#443060","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/443060"},{"name":"FEDORA-2009-7898","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00909.html"},{"name":"40936","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/40936/"},{"tags":["x_refsource_MISC"],"url":"http://voices.washingtonpost.com/securityfix/2009/07/stopgap_fix_for_critical_firef.html"},{"tags":["x_refsource_MISC"],"url":"http://isc.sans.org/diary.html?storyid=6796"},{"name":"266148","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-266148-1"},{"name":"35660","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/35660"},{"name":"9181","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/9181"},{"name":"35798","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35798"},{"tags":["x_refsource_CONFIRM"],"url":"http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/"},{"name":"ADV-2009-1868","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/1868"},{"name":"9137","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/9137"},{"tags":["x_refsource_MISC"],"url":"http://www.h-online.com/security/First-Zero-Day-Exploit-for-Firefox-3-5--/news/113761"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/2009/mfsa2009-41.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-2477","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=503286","refsource":"CONFIRM","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=503286"},{"name":"VU#443060","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/443060"},{"name":"FEDORA-2009-7898","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00909.html"},{"name":"40936","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/40936/"},{"name":"http://voices.washingtonpost.com/securityfix/2009/07/stopgap_fix_for_critical_firef.html","refsource":"MISC","url":"http://voices.washingtonpost.com/securityfix/2009/07/stopgap_fix_for_critical_firef.html"},{"name":"http://isc.sans.org/diary.html?storyid=6796","refsource":"MISC","url":"http://isc.sans.org/diary.html?storyid=6796"},{"name":"266148","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-266148-1"},{"name":"35660","refsource":"BID","url":"http://www.securityfocus.com/bid/35660"},{"name":"9181","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/9181"},{"name":"35798","refsource":"SECUNIA","url":"http://secunia.com/advisories/35798"},{"name":"http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/","refsource":"CONFIRM","url":"http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/"},{"name":"ADV-2009-1868","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/1868"},{"name":"9137","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/9137"},{"name":"http://www.h-online.com/security/First-Zero-Day-Exploit-for-Firefox-3-5--/news/113761","refsource":"MISC","url":"http://www.h-online.com/security/First-Zero-Day-Exploit-for-Firefox-3-5--/news/113761"},{"name":"http://www.mozilla.org/security/announce/2009/mfsa2009-41.html","refsource":"CONFIRM","url":"http://www.mozilla.org/security/announce/2009/mfsa2009-41.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-2477","datePublished":"2009-07-15T15:00:00.000Z","dateReserved":"2009-07-15T00:00:00.000Z","dateUpdated":"2024-08-07T05:52:14.977Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-07-15 15:30:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-94","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:3.5:*:*:*:*:*:*:*","matchCriteriaId":"76CD3BDF-A079-4EF3-ABDE-43CBDD08DB1F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"2477","Ordinal":"1","Title":"CVE-2009-2477","CVE":"CVE-2009-2477","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"2477","Ordinal":"1","NoteData":"js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.","Type":"Description","Title":"CVE-2009-2477"},{"CveYear":"2009","CveId":"2477","Ordinal":"2","NoteData":"2009-07-15","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"2477","Ordinal":"3","NoteData":"2017-09-18","Type":"Other","Title":"Modified"}]}}}