CVE-2009-2477

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:3.5:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-07-15 15:30

Updated : 2023-12-10 10:51


NVD link : CVE-2009-2477

Mitre link : CVE-2009-2477

CVE.ORG link : CVE-2009-2477


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')