Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-2477

Опубликовано: 15 июл. 2009
Источник: nvd
CVSS2: 9.3
EPSS Высокий

Описание

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mozilla:firefox:3.5:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.83034
Высокий

9.3 Critical

CVSS2

Дефекты

CWE-94

Связанные уязвимости

ubuntu
больше 16 лет назад

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.

redhat
больше 16 лет назад

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.

debian
больше 16 лет назад

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka ...

github
больше 3 лет назад

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.

EPSS

Процентиль: 99%
0.83034
Высокий

9.3 Critical

CVSS2

Дефекты

CWE-94