PT-2009-6655 · Mozilla+1 · Thunderbird+2

Peter Van Der Beken

+1

·

Published

1970-01-01

·

Updated

2025-06-25

·

CVE-2009-2466

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.0.12 Thunderbird versions prior to 3.0.12
Description The issue is related to the JavaScript engine and can cause a denial of service or possibly execute arbitrary code. It is related to vectors such as nsDOMClassInfo.cpp, JS HashTableRawLookup, MirrorWrappedNativeParent, and js LockGCThingRT. The vulnerability can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For Mozilla Firefox versions prior to 3.0.12, update to version 3.0.12 or later to resolve the issue. For Thunderbird versions prior to 3.0.12, update to version 3.0.12 or later to resolve the issue. As a temporary workaround, consider disabling JavaScript in the browser until a patch is available.

Exploit

Fix

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2015-01736
BDU:2015-01737
BDU:2015-01738
BDU:2015-01739
CVE-2009-2466
DSA-1840-1
RHSA-2009:1162
RHSA-2009:1163
RHSA-2009_1162
RHSA-2009_1163
RHSA-2010:0153
RHSA-2010:0154
RHSA-2010_0153
RHSA-2010_0154

Affected Products

Firefox
Red Hat
Thunderbird