AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-2975

MEDIUM · CVSS 5 EPSS 2.05%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-08-27 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-2975
Severity
MEDIUM
CVSS
5
EPSS
2.05%
Windows Chrome Firefox

Original NVD Description

Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value specifying a protocol associated with an external application, which allows remote attackers to cause a denial of service (memory consumption) via vectors involving a series of function calls that set this property, as demonstrated by (1) the chromehtml: protocol and (2) the aim: protocol.