Loading...
Loading...
js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.
July 15, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2009-2477
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.