9.3
CVSSv2

CVE-2009-1313

Published: 30/04/2009 Updated: 07/11/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote malicious users to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2009-1302.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.0.9

Vendor Advisories

Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic Updated firefox packages that fix one security issue are now available forRed Hat Enterprise Linux 4 and 5This update has been rated as having critical security impact by the RedHat Security Response Team D ...
It was discovered that the upstream security fixes in USN-764-1 introduced a regression which could cause the browser to crash If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program ...
Mozilla Foundation Security Advisory 2009-23 Crash in nsTextFrame::ClearTextRun() Announced April 27, 2009 Reporter Marc Gueury, Daniel Veditz Impact Critical Products Firefox Fixed in ...

Exploits

source: wwwsecurityfocuscom/bid/34743/info Mozilla Firefox is prone to a remote memory-corruption vulnerability Successful exploits will allow remote attackers to execute arbitrary code within the context of the affected browser or crash the browser, denying service to legitimate users <html><head><title> Bug 489647 ...