PT-2009-6655 · Mozilla+1 · Thunderbird+2
Peter Van Der Beken
+1
·
Published
1970-01-01
·
Updated
2025-06-25
·
CVE-2009-2466
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 3.0.12
Thunderbird versions prior to 3.0.12
Description
The issue is related to the JavaScript engine and can cause a denial of service or possibly execute arbitrary code. It is related to vectors such as
nsDOMClassInfo.cpp, JS HashTableRawLookup, MirrorWrappedNativeParent, and js LockGCThingRT. The vulnerability can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information.Recommendations
For Mozilla Firefox versions prior to 3.0.12, update to version 3.0.12 or later to resolve the issue.
For Thunderbird versions prior to 3.0.12, update to version 3.0.12 or later to resolve the issue.
As a temporary workaround, consider disabling JavaScript in the browser until a patch is available.
Exploit
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firefox
Red Hat
Thunderbird