CVE-2009-3382
HIGH 10.0EPSS 10.8%
layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
- CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 10.84% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2009-10-29
- Updated
- 2024-08-07