CVE-2009-1571
Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations.
- Affected products
- Firefox, Red Hat, Seamonkey, Suse, Thunderbird
- Mozilla Firefox
- = 3.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, 3.0.12, 3.0.13, 3.0.14, 3.0.15, 3.0.17, 3.5, 3.5.1, 3.5.2, 3.5.3, 3.5.4, 3.5.5, 3.5.6, 3.5.7
- Mozilla Seamonkey
- = 1.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.1, 1.1.1, 1.1.2, 1.1.3, 1.1.4
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 6.4% (93th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2010-02-21
CVE-2009-1571 at NVD
2 known exploits for CVE-2009-1571
Proof-of-concept code and exploit modules indexed by Sploitus