CVE-2009-0821

Firefox < 2.0.0.20 - Denial of Service via Nested window.print Calls

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-0821. PoCs published by b3hz4d.

AI-analyzed exploit summary This exploit demonstrates a denial-of-service vulnerability in Mozilla Firefox by triggering a crash via a malformed input to the `window.print()` function. The PoC uses a simple HTML button to execute the exploit when clicked.

Description

Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print function, as demonstrated by a window.print(window.print()) in the onclick attribute of an INPUT element.

Exploits (1)

exploitdb WORKING POC VERIFIED
by b3hz4d · htmldosmultiple
https://www.exploit-db.com/exploits/32836

This exploit demonstrates a denial-of-service vulnerability in Mozilla Firefox by triggering a crash via a malformed input to the `window.print()` function. The PoC uses a simple HTML button to execute the exploit when clicked.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Mozilla Firefox 2.0.0.20
No auth needed
Prerequisites: Victim must visit the malicious HTML page and interact with the button
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33969

Scores

EPSS 0.0529
EPSS Percentile 91.5%

Details

CWE
CWE-399
Status published
Products (45)
mozilla/firefox 0.1
mozilla/firefox 0.2
mozilla/firefox 0.3
mozilla/firefox 0.4
mozilla/firefox 0.5
mozilla/firefox 0.6
mozilla/firefox 0.6.1
mozilla/firefox 0.7
mozilla/firefox 0.7.1
mozilla/firefox 0.8
... and 35 more
Published Mar 05, 2009
Tracked Since Feb 18, 2026