CVE-2009-2662

The browser engine in Mozilla Firefox 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the TraceRecorder::snapshot function in js/src/jstracer.cpp, and unspecified other vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
mozillafirefox
𝑥
≤ 3.0.12
mozillafirefox
3.0.1
mozillafirefox
3.0.2
mozillafirefox
3.0.3
mozillafirefox
3.0.4
mozillafirefox
3.0.5
mozillafirefox
3.0.6
mozillafirefox
3.0.7
mozillafirefox
3.0.10
mozillafirefox
3.0.11
mozillafirefox
3.5.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
karmic
dne
jaunty
dne
intrepid
dne
hardy
not-affected
dapper
ignored
xulrunner-1.9
karmic
dne
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
dapper
dne
xulrunner-1.9.1
karmic
not-affected
jaunty
Fixed 1.9.1.3+build1+nobinonly-0ubuntu0.9.04.2
released
intrepid
dne
hardy
dne
dapper
dne