CVE-2009-2466

The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
mozillafirefox
𝑥
< 3.0.12
mozillathunderbird
𝑥
≤ 3.0.11
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
karmic
dne
jaunty
dne
intrepid
dne
hardy
ignored
dapper
ignored
mozilla-thunderbird
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
dapper
ignored
thunderbird
karmic
not-affected
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
dapper
dne
xulrunner-1.9
karmic
dne
jaunty
Fixed 1.9.0.12+build1+nobinonly-0ubuntu0.9.04.1
released
intrepid
Fixed 1.9.0.12+build1+nobinonly-0ubuntu0.8.10.2
released
hardy
Fixed 1.9.0.12+build1+nobinonly-0ubuntu0.8.04.1
released
dapper
dne
xulrunner-1.9.1
karmic
Fixed 1.9.1.1+build1+nobinonly-0ubuntu1
released
jaunty
Fixed 1.9.1.1+build1+nobinonly-0ubuntu0.9.04.1
released
intrepid
dne
hardy
dne
dapper
dne
References