9.3
CVSSv2

CVE-2009-2663

Published: 04/08/2009 Updated: 03/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

libvorbis before r16182, as used in Mozilla Firefox 3.5.x prior to 3.5.2 and other products, allows context-dependent malicious users to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 0.10.1

mozilla firefox 0.9.1

mozilla firefox 3.0.5

mozilla firefox 1.0.3

mozilla firefox 1.0.6

mozilla firefox 2.0.0.9

mozilla firefox 2.0_.6

mozilla firefox 2.0_.7

mozilla firefox 2.0_.9

mozilla firefox 2.0.0.11

mozilla firefox 0.10

mozilla firefox 0.8

mozilla firefox 2.0.0.20

mozilla firefox 1.0

mozilla firefox 1.0.4

mozilla firefox 1.0.7

mozilla firefox 2.0_.4

mozilla firefox 2.0_.5

mozilla firefox 2.0.0.10

mozilla firefox 2.0.0.16

mozilla firefox 0.3

mozilla firefox 1.5.0.5

mozilla firefox 1.5.0.2

mozilla firefox 1.5.0.3

mozilla firefox 1.5.4

mozilla firefox 1.5.1

mozilla firefox 2.0

mozilla firefox 2.0.0.4

mozilla firefox 2.0.0.3

mozilla firefox 3.0.3

mozilla firefox 3.0.11

mozilla firefox 1.5

mozilla firefox 3.0.4

mozilla firefox 3.0.1

mozilla firefox 2.0.0.19

mozilla firefox 0.9.2

mozilla firefox 1.0.1

mozilla firefox 3.0

mozilla firefox 1.0.5

mozilla firefox 2.0_.1

mozilla firefox 2.0_.10

mozilla firefox 3.0.7

mozilla firefox 2.0.0.17

mozilla firefox 0.7

mozilla firefox 0.7.1

mozilla firefox 0.2

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.10

mozilla firefox 1.5.3

mozilla firefox 1.5.0.7

mozilla firefox 1.5.5

mozilla firefox 2.0.0.6

mozilla firefox 2.0.0.5

mozilla firefox 3.0.6

mozilla firefox 1.4.1

mozilla firefox 0.4

mozilla firefox 0.5

mozilla firefox 1.5.0.11

mozilla firefox 2.0.0.7

mozilla firefox 1.5.2

mozilla firefox 1.5.0.8

mozilla firefox 1.8

mozilla firefox 1.5.8

mozilla firefox 0.9_rc

mozilla firefox 2.0.0.2

mozilla firefox 3.0.12

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.18

mozilla firefox 3.0.8

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.12

mozilla firefox 0.9

mozilla firefox 0.9.3

mozilla firefox 1.0.2

mozilla firefox 1.0.8

mozilla firefox 2.0_8

mozilla firefox 2.0.0.21

mozilla firefox 2.0.0.15

mozilla firefox 0.6.1

mozilla firefox 0.6

mozilla firefox 0.1

mozilla firefox 1.5.0.12

mozilla firefox 1.5.0.1

mozilla firefox 1.5.0.9

mozilla firefox 1.5.0.6

mozilla firefox 1.5.7

mozilla firefox 1.5.6

mozilla firefox 3.0.2

mozilla firefox 2.0.0.1

mozilla firefox 2.0.0.13

mozilla firefox 3.0.10

mozilla firefox 3.0.9

mozilla firefox

mozilla firefox 3.5

Vendor Advisories

It was discovered that libvorbis did not correctly handle certain malformed ogg files If a user were tricked into opening a specially crafted ogg file with an application that uses libvorbis, an attacker could execute arbitrary code with the user’s privileges (CVE-2009-2663) ...
Debian Bug report logs - #540958 libvorbis: CVE-2009-2663 vulnerability Package: libvorbis; Maintainer for libvorbis is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Michael S Gilbert <michaelsgilbert@gmailcom> Date: Mon, 10 Aug 2009 23:36:01 UTC Severity: grave Tags: security F ...
Debian Bug report logs - #669196 libvorbisidec: multiple longstanding unfixed security issues in libvorbis Package: libvorbisidec; Maintainer for libvorbisidec is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Wed, 18 Apr 2012 03:21:01 UTC ...
Lucas Adamski, Matthew Gregan, David Keeler, and Dan Kaminsky discovered that libvorbis, a library for the Vorbis general-purpose compressed audio codec, did not correctly handle certain malformed ogg files An attacher could cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted ogg fi ...
Mozilla Foundation Security Advisory 2009-63 Upgrade media libraries to fix memory safety bugs Announced October 27, 2009 Reporter Mozilla community and developers Impact Critical Products Firefox Fixed in ...
Mozilla Foundation Security Advisory 2009-45 Crashes with evidence of memory corruption (rv:1912/19013) Announced August 3, 2009 Reporter Mozilla developers and community Impact Critical Products Firefox Fixed in ...