CVE-2009-2404 describes a heap-based buffer overflow in the regular-expression parser of Mozilla Network Security Services (NSS) versions prior to 3.12.3. This vulnerability affects various applications including Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM). The flaw allows a remote SSL server to trigger a denial of service or potentially execute arbitrary code by presenting a specially crafted X.509 certificate with an excessively long domain name in the Common Name (CN) field. This vulnerability carries a critical CVSS score of 9.3, indicating a high severity. It can be exploited remotely with medium attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While the FAUCET Risk Score is 93/100, suggesting significant risk, the EPSS score is relatively low at 0.21024. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.12.3CPE matchmatch criteria | cpe:2.3:a:mozilla:network_security_services:3.12.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.