peter bassill · operator
$ cve CVE-2009-2477 JSON

CVE-2009-2477 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 42.7% (pctl 99)

Patch early

A public exploit exists.

Description

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS42.69% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2009-07-15
Last modified2026-06-16

Affected (1)

VendorProduct
mozillafirefox

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD