[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-0773Date: (C)2009-03-04   (M)2024-03-27


The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1021795
BID-33990
SECUNIA-34140
SECUNIA-34145
SECUNIA-34272
SECUNIA-34383
SECUNIA-34462
SECUNIA-34464
SECUNIA-34527
ADV-2009-0632
DSA-1751
DSA-1830
FEDORA-2009-3101
MDVSA-2009:075
MDVSA-2009:083
RHSA-2009:0315
SSA:2009-083-02
SSA:2009-083-03
SUSE-SA:2009:012
http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm
http://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.productID=154235&temp.releaseID=361845&temp.bucketID=126655&PAGE=Document
http://www.mozilla.org/security/announce/2009/mfsa2009-07.html
https://bugzilla.mozilla.org/show_bug.cgi?id=457521
https://bugzilla.mozilla.org/show_bug.cgi?id=467499
https://bugzilla.mozilla.org/show_bug.cgi?id=472787
oval:org.mitre.oval:def:10491
oval:org.mitre.oval:def:5856
oval:org.mitre.oval:def:5980
oval:org.mitre.oval:def:6141
oval:org.mitre.oval:def:6708

CPE    88
cpe:/a:mozilla:thunderbird:2.0.0.18
cpe:/a:mozilla:thunderbird:2.0.0.19
cpe:/a:mozilla:thunderbird:2.0.0.14
cpe:/a:mozilla:thunderbird:2.0.0.16
...
CWE    1
CWE-399
OVAL    58
oval:org.mitre.oval:def:5980
oval:org.mitre.oval:def:6141
oval:org.mitre.oval:def:5856
oval:org.secpod.oval:def:101728
...

© SecPod Technologies