PT-2009-4302 · Mozilla+1 · Firefox+1

Carsten Eiram

+1

·

Published

2009-06-11

·

Updated

2024-02-02

·

CVE-2009-1837

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Mozilla Firefox versions prior to 3.0.11
Description: A race condition in the NPObjWrapper NewResolve function might allow remote attackers to execute arbitrary code via a page transition during Java applet loading, related to a use-after-free vulnerability for memory associated with a destroyed Java object.
Recommendations: For versions prior to 3.0.11, update to version 3.0.11 or later to resolve the issue. As a temporary workaround, consider disabling Java applet loading until a patch is available. Restrict access to pages that load Java applets to minimize the risk of exploitation.

Exploit

Fix

RCE

Race Condition

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2009-1837
DSA-1820-1
RHSA-2009:1095
RHSA-2009_1095

Affected Products

Firefox
Red Hat