CVE Database
/

CVE-2009-0773

Back to search

CVE-2009-0773

Published: Mar 5, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang.

VendorProductVersions

n/a

n/a

affected
n/a

References

oval:org.mitre.oval:def:10491
vdb-entry
signature
x_refsource_OVAL
RHSA-2009:0315
vendor-advisory
x_refsource_REDHAT
SUSE-SA:2009:012
vendor-advisory
x_refsource_SUSE
DSA-1830
vendor-advisory
x_refsource_DEBIAN
oval:org.mitre.oval:def:6708
vdb-entry
signature
x_refsource_OVAL
ADV-2009-0632
vdb-entry
x_refsource_VUPEN
FEDORA-2009-3101
vendor-advisory
x_refsource_FEDORA
DSA-1751
vendor-advisory
x_refsource_DEBIAN
SSA:2009-083-02
vendor-advisory
x_refsource_SLACKWARE
34140
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:5856
vdb-entry
signature
x_refsource_OVAL
MDVSA-2009:083
vendor-advisory
x_refsource_MANDRIVA
34464
third-party-advisory
x_refsource_SECUNIA
34272
third-party-advisory
x_refsource_SECUNIA
34527
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:5980
vdb-entry
signature
x_refsource_OVAL
34145
third-party-advisory
x_refsource_SECUNIA
SSA:2009-083-03
vendor-advisory
x_refsource_SLACKWARE
34462
third-party-advisory
x_refsource_SECUNIA
1021795
vdb-entry
x_refsource_SECTRACK
MDVSA-2009:075
vendor-advisory
x_refsource_MANDRIVA
33990
vdb-entry
x_refsource_BID
34383
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:6141
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now