CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
91.3%
Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transition during Java applet loading, related to a use-after-free vulnerability for memory associated with a destroyed Java object.
Vendor | Product | Version | CPE |
---|---|---|---|
mozilla | firefox | * | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
debian | debian_linux | 5.0 | cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:* |
fedoraproject | fedora | 9 | cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:* |
fedoraproject | fedora | 10 | cpe:2.3:o:fedoraproject:fedora:10:*:*:*:*:*:*:* |
redhat | enterprise_linux | 4.0 | cpe:2.3:o:redhat:enterprise_linux:4.0:*:*:*:*:*:*:* |
redhat | enterprise_linux | 5.0 | cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:* |
redhat | enterprise_linux_desktop | 4.0 | cpe:2.3:o:redhat:enterprise_linux_desktop:4.0:*:*:*:*:*:*:* |
redhat | enterprise_linux_desktop | 5.0 | cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:* |
redhat | enterprise_linux_eus | 4.8 | cpe:2.3:o:redhat:enterprise_linux_eus:4.8:*:*:*:*:*:*:* |
redhat | enterprise_linux_eus | 5.3 | cpe:2.3:o:redhat:enterprise_linux_eus:5.3:*:*:*:*:*:*:* |
secunia.com/advisories/34241
secunia.com/advisories/35331
secunia.com/advisories/35415
secunia.com/advisories/35431
secunia.com/advisories/35468
secunia.com/secunia_research/2009-19/
slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468
sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1
www.debian.org/security/2009/dsa-1820
www.mozilla.org/security/announce/2009/mfsa2009-28.html
www.securityfocus.com/archive/1/504260/100/0/threaded
www.securityfocus.com/bid/35326
www.securityfocus.com/bid/35360
www.securitytracker.com/id?1022386
www.vupen.com/english/advisories/2009/1572
bugzilla.mozilla.org/show_bug.cgi?id=486269
bugzilla.redhat.com/show_bug.cgi?id=503579
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10628
rhn.redhat.com/errata/RHSA-2009-1095.html
www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.html
www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.html
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
91.3%