CVE-2009-2975
Last modified
CVE-2009-2975 is a vulnerability of currently unknown severity. Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value specifying a protocol associated with an external application, which allows remote attackers to cause a denial of service (memory consumption) via vectors involving a series of function calls that set this property, as demonstrated by (1) the chromehtml: protocol and (2) the aim: protocol.. EPSS estimates a 2.05% chance of exploitation in the next 30 days.
Description
Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value specifying a protocol associated with an external application, which allows remote attackers to cause a denial of service (memory consumption) via vectors involving a series of function calls that set this property, as demonstrated by (1) the chromehtml: protocol and (2) the aim: protocol.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 3.5.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-2975?
How severe is CVE-2009-2975?
How do I fix CVE-2009-2975?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-2967Multiple cross-site scripting (XSS) vulnerabilities in Build…
- CVE-2009-2968Directory traversal vulnerability in a support component in …
- CVE-2009-2970Stack-based buffer overflow in the GetUiDllVersion function …
- CVE-2009-2972in.lpd in the print service in Sun Solaris 8 and 9 allows re…
- CVE-2009-2973Google Chrome before 2.0.172.43 does not prevent SSL connect…
- CVE-2009-2974Google Chrome 1.0.154.65, 1.0.154.48, and earlier allows rem…
- CVE-2009-2976Cisco Aironet Lightweight Access Point (AP) devices send the…
- CVE-2009-2977The Cisco Security Monitoring, Analysis and Response System …
- CVE-2009-2978SQL injection vulnerability in SugarCRM 4.5.1o and earlier, …
- CVE-2009-2979Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, a…
- CVE-2009-2980Integer overflow in Adobe Reader and Acrobat 7.x before 7.1.…
- CVE-2009-2981Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7,…
Are you affected by CVE-2009-2975?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
