peter bassill · operator
$ cve CVE-2009-3373 JSON

CVE-2009-3373 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 15.5% (pctl 97)

Patch early

A public exploit exists.

Description

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS15.52% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2009-10-29
Last modified2026-06-16

Affected (2)

VendorProduct
mozillafirefox
mozillaseamonkey

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD