CVE-2009-3373 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 15.5% (pctl 97)
Patch early
A public exploit exists.
Description
Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 15.52% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-10-29 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | seamonkey |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mozilla Firefox 3.5.3 / SeaMonkey 1.1.17 - 'libpr0n' .GIF Parser Heap Buffer Overflow | 2009-10-27 |
References
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-272909-1
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:294
- http://www.mozilla.org/security/announce/2009/mfsa2009-56.html
- http://www.vupen.com/english/advisories/2009/3334
- https://bugzilla.mozilla.org/show_bug.cgi?id=511689
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10684
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6548
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-272909-1
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:294
- http://www.mozilla.org/security/announce/2009/mfsa2009-56.html
- http://www.vupen.com/english/advisories/2009/3334
- https://bugzilla.mozilla.org/show_bug.cgi?id=511689
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10684
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6548
→ the Explorer · watch your stack · NVD