[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-1044Date: (C)2009-03-23   (M)2023-12-22


Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage collection on objects that are still in use, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1021878
http://www.securityfocus.com/archive/1/502303/100/0/threaded
BID-34181
SECUNIA-34471
SECUNIA-34505
SECUNIA-34510
SECUNIA-34511
SECUNIA-34521
SECUNIA-34527
SECUNIA-34549
SECUNIA-34550
SECUNIA-34792
OSVDB-52896
ADV-2009-0864
DSA-1756
FEDORA-2009-3099
FEDORA-2009-3100
FEDORA-2009-3101
MDVSA-2009:084
RHSA-2009:0397
RHSA-2009:0398
SUSE-SA:2009:022
USN-745-1
http://blogs.zdnet.com/security/?p=2934
http://blogs.zdnet.com/security/?p=2941
http://cansecwest.com/index.html
http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009
http://dvlabs.tippingpoint.com/blog/2009/03/18/pwn2own-2009-day-1---safari-internet-explorer-and-firefox-taken-down-by-four-zero-day-exploits
http://news.cnet.com/8301-1009_3-10199652-83.html
http://support.avaya.com/elmodocs2/security/ASA-2009-113.htm
http://twitter.com/tippingpoint1/status/1351635812
http://www.h-online.com/security/Pwn2Own-2009-Safari-IE-8-and-Firefox-exploited--/news/112889
http://www.mozilla.org/security/announce/2009/mfsa2009-13.html
http://www.zerodayinitiative.com/advisories/ZDI-09-015
https://bugzilla.mozilla.org/show_bug.cgi?id=484320
oval:org.mitre.oval:def:11368

CPE    2
cpe:/a:mozilla:firefox:3.0.7
cpe:/o:microsoft:windows_7
CWE    1
CWE-399
OVAL    54
oval:org.secpod.oval:def:700355
oval:org.secpod.oval:def:400076
oval:org.secpod.oval:def:201965
oval:org.secpod.oval:def:200511
...

© SecPod Technologies