js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefox | Dec 10, 2025 | Jul 17, 2009 |
| Gentoo Linux | — | Upgrade dev-libs/nss.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/icecat.Upgrade net-libs/xulrunner.Upgrade www-client/mozilla-firefox.Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox-bin.Upgrade www-client/seamonkey-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/seamonkey.Upgrade www-client/firefox.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/thunderbird. | Oct 30, 2017 | Jul 15, 2009 |
| Mfsa2009 41 | — | Upgrade to Mozilla Firefox version 3.5.1 | Jun 14, 2012 | Jul 15, 2009 |
| Ubuntu | — | Upgrade firefox-3.5Upgrade xulrunner-1.9.1 | Nov 19, 2024 | Jul 15, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub