CVE-2009-1232

Firefox <= 3.0.10 - Denial of Service via Malformed XML Document

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-1232. PoCs published by Wojciech Pawlikowski.

AI-analyzed exploit summary This is a proof-of-concept exploit for a memory corruption vulnerability in Firefox's XUL (XML) parser, leading to a denial-of-service (DoS) condition. The exploit is distributed as a RAR file containing the PoC.

Description

Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption) via an XML document composed of a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 3.0.10 and earlier are also affected.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Wojciech Pawlikowski · textdoswindows
https://www.exploit-db.com/exploits/8306

This is a proof-of-concept exploit for a memory corruption vulnerability in Firefox's XUL (XML) parser, leading to a denial-of-service (DoS) condition. The exploit is distributed as a RAR file containing the PoC.

Classification
Working Poc 80%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Mozilla Firefox (version not specified, likely pre-2009)
No auth needed
Prerequisites: Victim must open the malicious XUL file in a vulnerable version of Firefox
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34522
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49521
Various Sources x_refsource_misc
http://websecurity.com.ua/3216/
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8306
Issue Tracking x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=485941

Scores

EPSS 0.1715
EPSS Percentile 95.1%

Details

CWE
CWE-20
Status published
Products (9)
mozilla/firefox 3.0 (4 CPE variants)
mozilla/firefox 3.0.1
mozilla/firefox 3.0.2
mozilla/firefox 3.0.3
mozilla/firefox 3.0.4
mozilla/firefox 3.0.5
mozilla/firefox 3.0.6
mozilla/firefox 3.0.7
mozilla/firefox 3.0.8
Published Apr 02, 2009
Tracked Since Feb 18, 2026