CVE-2009-2477

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
15/07/2009
Last modified:
09/04/2025

Description

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:3.5:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools