CVE-2009-0071
Mozilla Firefox <3.0.5 - DoS
Title source: llmDescription
Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1) queryCommandValue, (2) queryCommandState, or (3) queryCommandIndeterm call. NOTE: it was later reported that 3.0.6 and 3.0.7 are also affected.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Skylined · htmldosmultiple
https://www.exploit-db.com/exploits/8219
exploitdb
WORKING POC
VERIFIED
by Skylined · htmldosmultiple
https://www.exploit-db.com/exploits/8091
References (9)
Scores
EPSS
0.1086
EPSS Percentile
93.4%
Details
CWE
CWE-399
Status
published
Products (6)
mozilla/firefox
3.0 (4 CPE variants)
mozilla/firefox
3.0.1
mozilla/firefox
3.0.2
mozilla/firefox
3.0.3
mozilla/firefox
3.0.4
mozilla/firefox
3.0.5
Published
Jan 08, 2009
Tracked Since
Feb 18, 2026