10
CVSSv2

CVE-2009-3379

Published: 29/10/2009 Updated: 19/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x prior to 3.5.4, allow remote malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors. NOTE: this might overlap CVE-2009-2663.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.5.1

mozilla firefox 3.5.2

mozilla firefox 3.5.3

Vendor Advisories

Debian Bug report logs - #669196 libvorbisidec: multiple longstanding unfixed security issues in libvorbis Package: libvorbisidec; Maintainer for libvorbisidec is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Wed, 18 Apr 2012 03:21:01 UTC ...
It was discovered that libvorbis did not correctly handle ogg files with underpopulated Huffman trees If a user were tricked into opening a specially crafted ogg file with an application that uses libvorbis, an attacker could cause a denial of service (CVE-2008-2009) ...
Lucas Adamski, Matthew Gregan, David Keeler, and Dan Kaminsky discovered that libvorbis, a library for the Vorbis general-purpose compressed audio codec, did not correctly handle certain malformed ogg files An attacher could cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted ogg fi ...
Mozilla Foundation Security Advisory 2009-63 Upgrade media libraries to fix memory safety bugs Announced October 27, 2009 Reporter Mozilla community and developers Impact Critical Products Firefox Fixed in ...