CVE-2009-1837

HIGH
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transition during Java applet loading, related to a use-after-free vulnerability for memory associated with a destroyed Java object.

References

http://secunia.com/advisories/34241

http://secunia.com/advisories/35331

http://secunia.com/advisories/35415

http://secunia.com/advisories/35431

http://secunia.com/advisories/35468

http://secunia.com/secunia_research/2009-19/

http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468

http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1

http://www.debian.org/security/2009/dsa-1820

http://www.mozilla.org/security/announce/2009/mfsa2009-28.html

http://www.securityfocus.com/archive/1/504260/100/0/threaded

http://www.securityfocus.com/bid/35326

http://www.securityfocus.com/bid/35360

http://www.securitytracker.com/id?1022386

http://www.vupen.com/english/advisories/2009/1572

https://bugzilla.mozilla.org/show_bug.cgi?id=486269

https://bugzilla.redhat.com/show_bug.cgi?id=503579

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10628

https://rhn.redhat.com/errata/RHSA-2009-1095.html

https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.html

https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.html

Details

Source: MITRE

Published: 2009-06-12

Updated: 2018-10-10

Type: CWE-362

Risk Information

CVSS v2

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

Tenable Plugins

View all (18 total)

IDNameProductFamilySeverity
67869Oracle Linux 4 / 5 : firefox (ELSA-2009-1095)NessusOracle Linux Local Security Checks
high
63402GLSA-201301-01 : Mozilla Products: Multiple vulnerabilities (BEAST)NessusGentoo Local Security Checks
critical
60593Scientific Linux Security Update : firefox on SL4.x, SL5.x i386/x86_64NessusScientific Linux Local Security Checks
high
43755CentOS 5 : firefox (CESA-2009:1095)NessusCentOS Local Security Checks
high
41356SuSE 11 Security Update : MozillaFirefox (SAT Patch Number 1001)NessusSuSE Local Security Checks
high
40174openSUSE Security Update : MozillaFirefox (MozillaFirefox-1000)NessusSuSE Local Security Checks
high
39891openSUSE Security Update : MozillaFirefox (MozillaFirefox-1000)NessusSuSE Local Security Checks
high
39452Debian DSA-1820-1 : xulrunner - several vulnerabilitiesNessusDebian Local Security Checks
high
39443Mandriva Linux Security Advisory : firefox (MDVSA-2009:134)NessusMandriva Local Security Checks
high
39421Slackware 12.2 / current : mozilla-firefox (SSA:2009-167-01)NessusSlackware Local Security Checks
high
39406Fedora 9 : Miro-2.0.3-5.fc9 / blam-1.8.5-10.fc9.1 / chmsee-1.0.1-13.fc9 / devhelp-0.19.1-13.fc9 / etc (2009-6411)NessusFedora Local Security Checks
high
39403Fedora 10 : Miro-2.0.3-5.fc10 / blam-1.8.5-11.fc10 / devhelp-0.22-9.fc10 / epiphany-2.24.3-7.fc10 / etc (2009-6366)NessusFedora Local Security Checks
high
39390Ubuntu 8.04 LTS / 8.10 / 9.04 : firefox-3.0, xulrunner-1.9 vulnerabilities (USN-779-1)NessusUbuntu Local Security Checks
high
39376FreeBSD : mozilla -- multiple vulnerabilities (da185955-5738-11de-b857-000f20797ede)NessusFreeBSD Local Security Checks
high
39372Firefox < 3.0.11 Multiple VulnerabilitiesNessusWindows
high
39369RHEL 4 / 5 : firefox (RHSA-2009:1095)NessusRed Hat Local Security Checks
high
5072Mozilla Firefox < 3.0.11 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
800755Firefox < 3.0.11 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high