HIGH · 9.3

CVE-2009-2404

Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messe...

Vulnerability Description

Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MozillaNetwork Security Services3.12.3
AolInstant MessengerAll versions
GnomeEvolutionAll versions
MozillaFirefoxAll versions
MozillaSeamonkeyAll versions
MozillaThunderbirdAll versions
PidginPidginAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-2404?

CVE-2009-2404 is a vulnerability with a CVSS score of 9.3 (HIGH). Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messe...

How severe is CVE-2009-2404?

CVE-2009-2404 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-2404?

Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Network Security Services, Aol Instant Messenger, Gnome Evolution, Mozilla Firefox, Mozilla Seamonkey.