cvelist/2009/0xxx/CVE-2009-0071.json
2019-03-17 22:58:57 +00:00

102 lines
3.7 KiB
JSON

{
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2009-0071",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1) queryCommandValue, (2) queryCommandState, or (3) queryCommandIndeterm call. NOTE: it was later reported that 3.0.6 and 3.0.7 are also affected."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "8219",
"refsource": "EXPLOIT-DB",
"url": "https://www.exploit-db.com/exploits/8219"
},
{
"name": "20090107 Firefox 3.0.5 remote vulnerability via queryCommandState",
"refsource": "FULLDISC",
"url": "http://archives.neohapsis.com/archives/fulldisclosure/2009-01/0220.html"
},
{
"name": "https://bugzilla.mozilla.org/show_bug.cgi?id=456727",
"refsource": "CONFIRM",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=456727"
},
{
"name": "https://bugzilla.mozilla.org/show_bug.cgi?id=448329",
"refsource": "CONFIRM",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=448329"
},
{
"name": "8091",
"refsource": "EXPLOIT-DB",
"url": "https://www.exploit-db.com/exploits/8091"
},
{
"name": "33154",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/33154"
},
{
"name": "https://bugzilla.mozilla.org/show_bug.cgi?id=472507",
"refsource": "CONFIRM",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=472507"
},
{
"name": "20090107 Re: Firefox 3.0.5 remote vulnerability via queryCommandState",
"refsource": "FULLDISC",
"url": "http://archives.neohapsis.com/archives/fulldisclosure/2009-01/0223.html"
},
{
"name": "20090107 Re: Firefox 3.0.5 remote vulnerability via queryCommandState",
"refsource": "FULLDISC",
"url": "http://archives.neohapsis.com/archives/fulldisclosure/2009-01/0224.html"
}
]
}
}