CVE-2009-3382

layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
mozillafirefox
3.0.1
mozillafirefox
3.0.2
mozillafirefox
3.0.3
mozillafirefox
3.0.4
mozillafirefox
3.0.5
mozillafirefox
3.0.6
mozillafirefox
3.0.7
mozillafirefox
3.0.8
mozillafirefox
3.0.9
mozillafirefox
3.0.10
mozillafirefox
3.0.11
mozillafirefox
3.0.12
mozillafirefox
3.0.13
mozillafirefox
3.0.14
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox-3.0
karmic
dne
jaunty
Fixed 3.0.15+nobinonly-0ubuntu0.9.04.1
released
intrepid
Fixed 3.0.15+nobinonly-0ubuntu0.8.10.1
released
hardy
Fixed 3.0.15+nobinonly-0ubuntu0.8.04.1
released
dapper
dne
xulrunner-1.9
karmic
dne
jaunty
Fixed 1.9.0.15+nobinonly-0ubuntu0.9.04.1
released
intrepid
Fixed 1.9.0.15+nobinonly-0ubuntu0.8.10.1
released
hardy
Fixed 1.9.0.15+nobinonly-0ubuntu0.8.04.1
released
dapper
dne