CVE-2009-1044: Firefox XUL garbage collection issue (cansecwest pwn2own)

Severity: Critical

CVSS Score: 9.3

Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage collection on objects that are still in use, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.