CVE-2009-1044

EUVD-2009-1045
Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage collection on objects that are still in use, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
3.0.7
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
dapper
Fixed 1.5.dfsg+1.5.0.15~prepatch080614l-0ubuntu1
released
gutsy
Fixed 2.0.0.21~tb.21.308+nobinonly-0ubuntu0.7.10.1
released
hardy
ignored
intrepid
dne
jaunty
dne
karmic
dne
lucid
not-affected
maverick
not-affected
natty
not-affected
xulrunner
dapper
dne
gutsy
Fixed 1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1
released
hardy
Fixed 1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.04.1
released
intrepid
Fixed 1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.10.1
released
jaunty
ignored
karmic
ignored
lucid
dne
maverick
dne
natty
dne
xulrunner-1.9
dapper
dne
gutsy
ignored
hardy
Fixed 1.9.0.8+nobinonly-0ubuntu0.8.04.1
released
intrepid
Fixed 1.9.0.8+nobinonly-0ubuntu0.8.10.1
released
jaunty
Fixed 1.9.0.8+nobinonly-0ubuntu1
released
karmic
dne
lucid
dne
maverick
dne
natty
dne
xulrunner-1.9.1
dapper
dne
gutsy
dne
hardy
dne
intrepid
dne
jaunty
Fixed 1.9.1+nobinonly-0ubuntu0.9.04.1
released
karmic
Fixed 1.9.1~rc2+nobinonly-0ubuntu1
released
lucid
dne
maverick
dne
natty
dne
Common Weakness Enumeration
References