CVE-2009-0071

Mozilla Firefox <3.0.5 - DoS

Title source: llm

Description

Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1) queryCommandValue, (2) queryCommandState, or (3) queryCommandIndeterm call. NOTE: it was later reported that 3.0.6 and 3.0.7 are also affected.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Skylined · htmldosmultiple
https://www.exploit-db.com/exploits/8219
exploitdb WORKING POC VERIFIED
by Skylined · htmldosmultiple
https://www.exploit-db.com/exploits/8091

Scores

EPSS 0.1086
EPSS Percentile 93.4%

Details

CWE
CWE-399
Status published
Products (6)
mozilla/firefox 3.0 (4 CPE variants)
mozilla/firefox 3.0.1
mozilla/firefox 3.0.2
mozilla/firefox 3.0.3
mozilla/firefox 3.0.4
mozilla/firefox 3.0.5
Published Jan 08, 2009
Tracked Since Feb 18, 2026