Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted document, related to a certain pointer misinterpretation.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade xulrunner-devel-unstableUpgrade xulrunnerUpgrade xulrunner-develUpgrade firefox | Dec 1, 2016 | Jul 22, 2009 |
| Gentoo Linux | — | Upgrade mail-client/mozilla-thunderbird-bin.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/thunderbird-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox.Upgrade net-libs/xulrunner.Upgrade www-client/icecat.Upgrade www-client/seamonkey-bin.Upgrade dev-libs/nss.Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/seamonkey.Upgrade www-client/firefox. | Oct 30, 2017 | Jul 22, 2009 |
| Mfsa2009 37 | — | Upgrade to Mozilla Firefox version 3.0.12Upgrade to Mozilla Firefox version 3.5 | Jun 14, 2012 | Jul 22, 2009 |
| Oracle_linux | — | Upgrade xulrunner-develUpgrade firefoxUpgrade xulrunner-devel-unstableUpgrade xulrunner | Oct 16, 2024 | Jul 22, 2009 |
| Suse | — | Upgrade libidlUpgrade MozillaFirefoxUpgrade gconf2Upgrade mozilla-xulrunner190-32bitUpgrade mozilla-xulrunner191-gnomevfsUpgrade mozilla-xulrunner192-translationsUpgrade mozilla-xulrunner191-32bitUpgrade mozilla-nspr-x86Upgrade mozilla-xulrunner191Upgrade orbit2Upgrade mozilla-xulrunner190Upgrade MozillaFirefox-translationsUpgrade mozilla-nss-toolsUpgrade mozilla-xulrunner192-32bitUpgrade mozilla-nss-x86Upgrade mozilla-xulrunner190-x86Upgrade libfreebl3-x86Upgrade mozilla-nssUpgrade libfreebl3-32bitUpgrade gconf2-32bitUpgrade orbit2-x86Upgrade mozilla-xulrunner190-gnomevfsUpgrade libidl-32bitUpgrade libidl-x86Upgrade mozilla-nspr-32bitUpgrade mozilla-xulrunner191-translationsUpgrade mozilla-xulrunner190-translationsUpgrade MozillaFirefox-branding-SLEDUpgrade mozilla-xulrunner192-x86Upgrade mozilla-nsprUpgrade libfreebl3Upgrade mozilla-xulrunner191-x86Upgrade gconf2-x86Upgrade mozilla-xulrunner192-gnomeUpgrade mozilla-nss-32bitUpgrade orbit2-32bitUpgrade mozilla-xulrunner192 | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade firefox-3.0Upgrade xulrunner-1.9Upgrade abrowser | Nov 8, 2024 | Jul 22, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub