272909Vendor advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-272909-1 CVE-2009-3382
Mozilla Firefox 3.0.14 - Remote Memory Corruption
Record summary
CVE-2009-3382 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMozilla Firefox 3.0.14 - Remote Memory CorruptionExploitDB exploitby Carsten BookNot analyzed1 file
References
7mozilla.orgConfirmation
http://www.mozilla.org/security/announce/2009/mfsa2009-64.html ADV-2009-3334vdb entry
http://www.vupen.com/english/advisories/2009/3334 bugzilla.mozilla.orgConfirmation
https://bugzilla.mozilla.org/show_bug.cgi?id=514960 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-3382 oval:org.mitre.oval:def:11219vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11219 oval:org.mitre.oval:def:5581vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5581