VDB
CVE-2009-2535
CVE-2009-2535
PUBLISHED
CVSS 5 MEDIUM
Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
EPSS 8.24% · 92.4th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
8.24%
92.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| mozilla | firefox | 1.5.0.4, 0, 0.1 |
| n/a | n/a | n/a |
| mozilla | thunderbird | 1.5.0.12, 1.5.0.8, 1.5.0.9 |
| mozilla | seamonkey | 1.0, 1.0, 1.0 |
Exploit Intelligence
- CIRCL confirmed: CVE-2009-2535 (circl-sighting)
- http://www.g-sec.lu/one-bug-to-rule-them-all.html (circl)
- 20090715 Re:[GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... (circl)
- 20090716 Re[2]: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... (circl)
- 20090715 [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... (circl)
- 20090715 Re: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... (circl)
- https://bugzilla.mozilla.org/show_bug.cgi?id=460713 (circl)
- Multiple Browsers - Denial of Service - Multiple dos Exploit (variot)
- Multiple Browsers - Denial of Service - Multiple dos Exploit (variot)
- Multiple Browsers - Denial of Service - Multiple dos Exploit (variot)
…and 2 more exploits
Timeline
- Jun 17, 2009 CVE Published
- Jun 17, 2009 PoC Published
- Jul 15, 2009 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- http://www.g-sec.lu/one-bug-to-rule-them-all.html url
- 20090715 Re:[GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... mailing-list
- 20090716 Re[2]: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... mailing-list
- 9160 exploit
- 20090715 [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... mailing-list
- 20090715 Re: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... mailing-list
- https://bugzilla.mozilla.org/show_bug.cgi?id=460713 url
- https://nvd.nist.gov/vuln/detail/CVE-2009-2535 advisory