Vulnerabilities > CVE-2005-2414 - Denial-Of-Service vulnerability in Xpcom

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
high complexity
xpcom
exploit available

Summary

Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV tags, which causes part of the currently rendering page and referenced objects to be deleted.

Vulnerable Configurations

Part Description Count
Application
Xpcom
1

Exploit-Db

descriptionXPCOM - Race Condition. CVE-2005-2414. Webapps exploit for PHP platform
idEDB-ID:43831
last seen2018-01-24
modified2015-07-21
published2015-07-21
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/43831/
titleXPCOM - Race Condition