CVE-2009-1837
HIGHMozilla Firefox < 3.0.11 - Race Condition
Title source: ruleDescription
Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transition during Java applet loading, related to a use-after-free vulnerability for memory associated with a destroyed Java object.
References (21)
... and 1 more
Scores
CVSS v3
7.5
EPSS
0.0218
EPSS Percentile
84.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-362
CWE-416
Status
draft
Affected Products (15)
mozilla/firefox
< 3.0.11
debian/debian_linux
fedoraproject/fedora
fedoraproject/fedora
redhat/enterprise_linux
redhat/enterprise_linux
redhat/enterprise_linux_desktop
redhat/enterprise_linux_desktop
redhat/enterprise_linux_eus
redhat/enterprise_linux_eus
redhat/enterprise_linux_server
redhat/enterprise_linux_server
redhat/enterprise_linux_server_aus
redhat/enterprise_linux_workstation
redhat/enterprise_linux_workstation
Timeline
Published
Jun 12, 2009
Tracked Since
Feb 18, 2026