CVE-2009-2477
EXPLOITEDMozilla Firefox <3.5.1 - RCE
Title source: llmDescription
js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.
Exploits (6)
exploitdb
WORKING POC
VERIFIED
by Hacker Fantastic · htmllocallinux
https://www.exploit-db.com/exploits/40936
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16299
exploitdb
WORKING POC
VERIFIED
by netsoul · perlremotewindows
https://www.exploit-db.com/exploits/9214
exploitdb
WORKING POC
VERIFIED
by David Kennedy (ReL1K) · pythonremotewindows
https://www.exploit-db.com/exploits/9181
exploitdb
WORKING POC
VERIFIED
by Sberry · htmlremotewindows
https://www.exploit-db.com/exploits/9137
metasploit
WORKING POC
NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/firefox_escape_retval.rb
References (15)
Scores
EPSS
0.8331
EPSS Percentile
99.3%
Details
VulnCheck KEV
2010-05-01
CWE
CWE-94
Status
published
Products (1)
mozilla/firefox
3.5
Published
Jul 15, 2009
Tracked Since
Feb 18, 2026