PT-2009-4884 · Mozilla · Firefox

Hacker Fantastic

·

Publicado

2009-07-15

·

Atualizado

2017-09-19

·

CVE-2009-2477

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.5.1
Description The issue is related to the Just-in-time (JIT) JavaScript compiler, also known as TraceMonkey, in Mozilla Firefox. It allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations. This can be demonstrated by a document containing specific elements.
Recommendations For versions prior to 3.5.1, update to version 3.5.1 or later to resolve the issue.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2477

Produtos afetados

Firefox