Vulnerability Name: | CVE-2009-1232 (CCN-49521) | ||||||||
Assigned: | 2009-03-30 | ||||||||
Published: | 2009-03-30 | ||||||||
Updated: | 2017-09-29 | ||||||||
Summary: | Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption) via an XML document composed of a long series of start-tags with no corresponding end-tags. Note: it was later reported that 3.0.10 and earlier are also affected. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:POC/RL:U/RC:UR)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:POC/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-1232 Source: MISC Type: Exploit http://milw0rm.com/sploits/2009-Firefox-XUL-0day-PoC.rar Source: MISC Type: UNKNOWN http://websecurity.com.ua/3216/ Source: CCN Type: Mozilla Web site Mozilla Firefox Source: CCN Type: OSVDB ID: 53230 Mozilla Firefox XUL Parser XML Document Handling Memory Corruption DoS Source: BID Type: Exploit 34522 Source: CCN Type: BID-34522 Mozilla Firefox XUL Parser Start Tags Denial of Service Vulnerability Source: CCN Type: Bugzilla@Mozilla Bug 485941 Possible XML XUL parser memory corruption (DoS) Source: MISC Type: UNKNOWN https://bugzilla.mozilla.org/show_bug.cgi?id=485941 Source: XF Type: UNKNOWN firefox-xml-dos(49521) Source: XF Type: UNKNOWN firefox-xml-dos(49521) Source: EXPLOIT-DB Type: UNKNOWN 8306 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |