4.3
CVSSv2

CVE-2009-1232

Published: 02/04/2009 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Mozilla Firefox 3.0.8 and previous versions 3.0.x versions allows remote malicious users to cause a denial of service (memory corruption) via an XML document composed of a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 3.0.10 and previous versions are also affected.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.0

mozilla firefox 3.0.1

mozilla firefox 3.0.5

mozilla firefox 3.0.4

mozilla firefox 3.0.8

mozilla firefox 3.0.3

mozilla firefox 3.0.2

mozilla firefox 3.0.7

mozilla firefox 3.0.6

Exploits

Firefox memory corruption PoC/DoS in XUL (XML) parser githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/8306rar (2009-Firefox-XUL-0day-PoCrar) # milw0rmcom [2009-03-30] ...