CVE-2009-2477

EXPLOITED

Mozilla Firefox <3.5.1 - RCE

Title source: llm

Description

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.

Exploits (6)

exploitdb WORKING POC VERIFIED
by Hacker Fantastic · htmllocallinux
https://www.exploit-db.com/exploits/40936
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16299
exploitdb WORKING POC VERIFIED
by netsoul · perlremotewindows
https://www.exploit-db.com/exploits/9214
exploitdb WORKING POC VERIFIED
by David Kennedy (ReL1K) · pythonremotewindows
https://www.exploit-db.com/exploits/9181
exploitdb WORKING POC VERIFIED
by Sberry · htmlremotewindows
https://www.exploit-db.com/exploits/9137
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/firefox_escape_retval.rb

Scores

EPSS 0.8331
EPSS Percentile 99.3%

Details

VulnCheck KEV 2010-05-01
CWE
CWE-94
Status published
Products (1)
mozilla/firefox 3.5
Published Jul 15, 2009
Tracked Since Feb 18, 2026