CVE-2009-2464: Critical severity firefox vulnerability
The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2464?
CVE-2009-2464 has a high severity due to potential memory corruption and application crash leading to denial of service or arbitrary code execution.
How do I fix CVE-2009-2464?
To fix CVE-2009-2464, users should update their Mozilla Firefox, SeaMonkey, or Thunderbird to the latest version available that has the vulnerability patched.
What versions are affected by CVE-2009-2464?
CVE-2009-2464 affects multiple versions including Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird before a specific update.
Can CVE-2009-2464 be exploited remotely?
Yes, CVE-2009-2464 can be exploited remotely by attackers through specific vectors while loading resources in affected software.
Is there a workaround for CVE-2009-2464?
There is no specific workaround for CVE-2009-2464, so the best approach is to update to the latest version of the affected applications.