RETIRED: Mozilla Firefox MFSA 2009-34, -35, -36, -37, -39, -40 Multiple Vulnerabilities

BID:35758

CVE-2009-2466 |

Info

RETIRED: Mozilla Firefox MFSA 2009-34, -35, -36, -37, -39, -40 Multiple Vulnerabilities

Bugtraq ID: 35758
Class: Unknown
CVE:
Remote: Yes
Local: No
Published: Jul 21 2009 12:00AM
Updated: Jul 22 2009 09:36PM
Credit: Martijn Wargers, Arno Renevier, Jesse Ruderman, Olli Pettay, Blake Kaplan, monarch2020, Christophe Charron, Yongqian Li, John Senchak, Peter Van der Beken, Mike Shaver, Jeff Walden, Carsten Book, Attila Suszter, Will Drewry, PenPal, moz_bug_r_a4
Vulnerable: Mozilla Firefox 3.5
Mozilla Firefox 3.0.11
Mozilla Firefox 3.0.10
Mozilla Firefox 3.0.9
Mozilla Firefox 3.0.8
Mozilla Firefox 3.0.7 Beta
Mozilla Firefox 3.0.7
Mozilla Firefox 3.0.6
Mozilla Firefox 3.0.5
Mozilla Firefox 3.0.4
Mozilla Firefox 3.0.3
Mozilla Firefox 3.0.2
Mozilla Firefox 3.0.1
Mozilla Firefox 3.0 Beta 5
Mozilla Firefox 3.0
Not Vulnerable: Mozilla Firefox 3.0.12

Discussion

RETIRED: Mozilla Firefox MFSA 2009-34, -35, -36, -37, -39, -40 Multiple Vulnerabilities

The Mozilla Foundation has released multiple advisories to address vulnerabilities in Firefox.

This BID is being retired; the following individual records now document these issues:

34870 Pango 'pango_glyph_string_set_size()' Integer Overflow Vulnerability
35765 Mozilla Firefox and Thunderbird Multiple Remote Memory Corruption Vulnerabilities
35766 Mozilla Firefox 'setTimeout()' Remote Code Execution Vulnerability
35767 Mozilla Firefox Flash Player Unloading Remote Code Execution Vulnerability
35769 Mozilla Firefox and Thunderbird Remote Integer Overflow Vulnerability
35770 Mozilla Firefox/Thunderbird Double Frame Construction Memory Corruption Vulnerabilities
35772 Mozilla Firefox 'watch()' and ' __defineSetter__ ()' Functions Remote Code Execution Vulnerability
35773 Mozilla Firefox 'XPCCrossOriginWrapper' Multiple Cross Domain Scripting Vulnerabilities
35774 CoreGraphics Font Glyph Rendering Library Multiple Remote Code Execution Vulnerabilities
35775 Mozilla Firefox and Thunderbird RDF File Handling Remote Memory Corruption Vulnerability
35776 Mozilla Firefox/Thunderbird JavaScript Engine Memory Corruption Vulnerabilities

Exploit / POC

RETIRED: Mozilla Firefox MFSA 2009-34, -35, -36, -37, -39, -40 Multiple Vulnerabilities

Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

Solution / Fix

RETIRED: Mozilla Firefox MFSA 2009-34, -35, -36, -37, -39, -40 Multiple Vulnerabilities

Solution:
Updates are available. Please see the references for details.

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report