Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-1044

28
FAUCET Score

CVE-2009-1044 describes a critical arbitrary code execution vulnerability in Mozilla Firefox 3.0.7 running on Windows 7. The flaw, demonstrated during a PWN2OWN competition, stems from the _moveToEdgeShift XUL tree method, which improperly triggers garbage collection on in-use objects. With a CVSS score of 9.3, this vulnerability is highly severe, allowing unauthenticated remote attackers to achieve complete compromise of confidentiality, integrity, and availability with medium attack complexity. While no public exploit intelligence like Metasploit or ExploitDB entries exist, its demonstration at a prominent hacking competition indicates its exploitability. Community discussion and media coverage for this CVE are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
3.0.7CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:3.0.7:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
6.49%
Probability of exploitation in next 30 days
EPSS Percentile
93.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0649 is in the 68th percentile among its peer group of 8,920 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

mozillapatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: seamonkey-0:1.0.9-0.32.el2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: seamonkey-0:1.0.9-0.36.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: firefox-0:3.0.7-3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: seamonkey-0:1.0.9-40.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: xulrunner-0:1.9.0.7-3.el5
View patch

Vendor Advisories (1)

redhatCVE-2009-1044Critical

Firefox XUL garbage collection issue (cansecwest pwn2own)

Mar 27, 2009

References

blogs.zdnet.com / security
blogs.zdnet.com / security
cansecwest.com / index.html
dvlabs.tippingpoint.com / blog/2009/02/25/pwn2own-2009
dvlabs.tippingpoint.com / blog/2009/03/18/pwn2own-2009-day-1---safari-internet-explorer-and-firefox-taken-down-by-four-zero-day-exploits
lists.opensuse.org / opensuse-security-announce/2009-04/msg00008.html
news.cnet.com / 8301-1009_3-10199652-83.html
osvdb.org / 52896
bugzilla.mozilla.org / show_bug.cgi
Patch
secunia.com / advisories/34471
Vendor Advisory
secunia.com / advisories/34505
Vendor Advisory
secunia.com / advisories/34510
Vendor Advisory
secunia.com / advisories/34511
Vendor Advisory
secunia.com / advisories/34521
Vendor Advisory
secunia.com / advisories/34527
Vendor Advisory
secunia.com / advisories/34549
Vendor Advisory
secunia.com / advisories/34550
Vendor Advisory
secunia.com / advisories/34792
Vendor Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11368
support.avaya.com / elmodocs2/security/ASA-2009-113.htm
redhat.com / archives/fedora-package-announce/2009-March/msg01023.html
redhat.com / archives/fedora-package-announce/2009-March/msg01040.html
redhat.com / archives/fedora-package-announce/2009-March/msg01077.html
twitter.com / tippingpoint1/status/1351635812
debian.org / security/2009/dsa-1756
h-online.com / security/Pwn2Own-2009-Safari-IE-8-and-Firefox-exploited--/news/112889
mandriva.com / security/advisories
mozilla.org / security/announce/2009/mfsa2009-13.html
PatchVendor Advisory
redhat.com / support/errata/RHSA-2009-0397.html
redhat.com / support/errata/RHSA-2009-0398.html
securityfocus.com / archive/1/502303/100/0/threaded
securityfocus.com / bid/34181
Patch
securitytracker.com / id
ubuntu.com / usn/usn-745-1
vupen.com / english/advisories/2009/0864
PatchVendor Advisory
zerodayinitiative.com / advisories/ZDI-09-015