CVE-2009-2479

Mozilla Firefox <3.5.2 - DoS

Title source: llm

Description

Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exception and application crash) via a long Unicode string argument to the write method. NOTE: this was originally reported as a stack-based buffer overflow. NOTE: on Linux and Mac OS X, a crash resulting from this long string reportedly occurs in an operating-system library, not in Firefox.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Andrew Haynes · htmldoswindows
https://www.exploit-db.com/exploits/9158

Scores

EPSS 0.1119
EPSS Percentile 93.5%

Details

CWE
CWE-119
Status published
Products (19)
mozilla/firefox 3.0.1
mozilla/firefox 3.0.2
mozilla/firefox 3.0.3
mozilla/firefox 3.0.4
mozilla/firefox 3.0.5
mozilla/firefox 3.0.6
mozilla/firefox 3.0.7
mozilla/firefox 3.0.8
mozilla/firefox 3.0.9
mozilla/firefox 3.0.10
... and 9 more
Published Jul 16, 2009
Tracked Since Feb 18, 2026