CVE-2009-5017
Mozilla Firefox < 3.6 - XSS
Title source: ruleDescription
Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.
References (4)
Scores
EPSS
0.0017
EPSS Percentile
37.4%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
mozilla/firefox
< 3.6
mozilla/firefox
n/a/n/a
Timeline
Published
Nov 12, 2010
Tracked Since
Feb 18, 2026