CVE-2009-3380: Critical severity firefox vulnerability
Published Oct 29, 2009
·Updated
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Affected Software
17 affected components
Mozilla Firefox=3.5.3
Mozilla Firefox=3.0.7
Mozilla Firefox=3.0.9
Mozilla Firefox=3.0.8
Mozilla Firefox=3.0.4
Mozilla Firefox=3.0.5
Mozilla Firefox=3.5.1
Mozilla Firefox=3.0.14
Mozilla Firefox=3.5.2
Mozilla Firefox=3.0.10
Mozilla Firefox=3.0.12
Mozilla Firefox=3.0.3
Mozilla Firefox=3.0.6
Mozilla Firefox=3.0.1
Mozilla Firefox=3.0.2
Mozilla Firefox=3.0.13
Mozilla Firefox=3.0.11
Remediation
Event History
Oct 29, 2009
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3380?
CVE-2009-3380 has a severity that can lead to denial of service and potential arbitrary code execution.
2
How do I fix CVE-2009-3380?
To fix CVE-2009-3380, upgrade to Mozilla Firefox version 3.0.15 or 3.5.4 or later.
3
What versions of Firefox are affected by CVE-2009-3380?
CVE-2009-3380 affects Firefox versions 3.0.x before 3.0.15 and 3.5.x before 3.5.4.
4
Can CVE-2009-3380 be exploited remotely?
Yes, CVE-2009-3380 allows remote attackers to exploit the vulnerability through unknown vectors.
5
What types of attacks can CVE-2009-3380 facilitate?
CVE-2009-3380 can facilitate denial of service attacks resulting in application crashes.