Published: 29/10/2009 Updated: 19/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x prior to 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

Affected Products

Vendor Product Versions
MozillaFirefox3.5, 3.5.1, 3.5.2, 3.5.3

Vendor Advisories

USN-853-1 fixed vulnerabilities in Firefox and Xulrunner The upstream changes introduced regressions that could lead to crashes when processing certain malformed GIF images, fonts and web pages This update fixes the problem ...
Alin Rad Pop discovered a heap-based buffer overflow in Firefox when it converted strings to floating point numbers If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program (CVE-2009-1563) ...
Upgrade media libraries to fix memory safety bugs Announced October 27, 2009 Reporter Mozilla community and developers Impact Critical Products Firefox Fixed in ...